
CVE-2026-37504 Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is acce… https://www.cve.org/CVERecord?id=CVE-2026-37504
Post summary
The post discloses CVE-2026-37504, which allows attackers to expose a server authentication token via a GET parameter in V2Board up to version 1.7.4, indicating a potential for unauthorized access.
