合集-漏洞报告
摘要:CVE Request 2: Path Traversal in read_json Module Title: Path Traversal Vulnerability in read_json Module Due to Unvalidated File Path Affected Compon
阅读全文
摘要:Title: Path Traversal Vulnerability in read_parquet Module Due to Unvalidated File Path Affected Component: module/read_parquet.go, Prepare Method Att
阅读全文
摘要:Title: Path Traversal Vulnerability in read_toml Module Due to Unvalidated File Path Affected Component: module/read_toml.go, Prepare Method Attack Ve
阅读全文
摘要:Title: Path Traversal Vulnerability in read_log Module Due to Unvalidated File Path Affected Component: module/read_log.go, Prepare Method Attack Vect
阅读全文
摘要:product:dreamercms url: https://github.com/iteachyou-wjn/dreamer_cms star: 1k Vulnerability Submission Report Product: dreamer_cms URL: http://localho
阅读全文
摘要:product: jeecgboot url: https://github.com/jeecgboot/JeecgBoot stars: 43.7k English Report Product: JeecgBoot URL: /api/system/sendWebSocketMsg Title:
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5 Vulnerability Report Product: platform URL: http://host/attributecate
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5 Vulnerability Report Product: platform URL: http://host/attribute/que
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5 Vulnerability Report Product: platform URL: http://host/brand/queryAl
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5 Vulnerability Report Product: platform URL: http://host/channel/query
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5 Vulnerability Report Product: platform URL: http://host/comment/query
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/commentpicture/queryAll Title: Broken Function Level Authorization in CommentPictureController
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5 Vulnerability Report Product: platform URL: http://host/coupon/queryA
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5 Vulnerability Report Product: platform URL: http://host/coupongoods/q
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/goods/queryAll Title: Broken Function Level Authorization in GoodsController's queryAll Method
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/goods/historyList Title: Broken Function Level Authorization in GoodsController's historyList
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/goodsgallery/queryAll Title: Broken Function Level Authorization in GoodsGalleryController's q
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/goodsissue/queryAll Title: Broken Function Level Authorization in GoodsIssueController's query
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/goodsspecification/queryAll Title: Broken Function Level Authorization in GoodsSpecificationCo
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/keywords/queryAll Title: Broken Function Level Authorization in KeywordsController's queryAll
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/order/queryAll Title: Broken Function Level Authorization in OrderController's queryAll Method
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/ordergoods/queryAll Title: Broken Function Level Authorization in OrderGoodsController's query
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/product/queryAll Title: Broken Function Level Authorization in ProductController's queryAll Me
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/shipping/queryAll Title: Broken Function Level Authorization in ShippingController's queryAll
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/specification/queryAll Title: Broken Function Level Authorization in SpecificationController's
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/sys/macro/queryAll Title: Broken Function Level Authorization in SysMacroController's queryAll
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5k Vulnerability Report Product: platform URL: http://host/sys/menu/que
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5 Vulnerability Report Product: platform URL: http://host/sys/smslog/qu
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5 Vulnerability Report Product: platform URL: http://host/topiccategory
阅读全文
摘要:Product:platform v1.0 url:https://gitee.com/fuyang_lipengjun/platform star: 27.5 Vulnerability Report Product: platform URL: http://host/user/queryAll
阅读全文
摘要:Vulnerability Report Product: platform URL: http://host/userlevel/queryAll Title: Broken Function Level Authorization in UserLevelController's queryAl
阅读全文
摘要:* 标题:jeecgboot 3.9.0 bfla https://github.com/jeecgboot/JeecgBoot/issues/9196 44.8k jeecg-boot 最新版本(master分支) 分支: master 问题描述: 【严重安全漏洞】未授权访问+权限绕过导致任意用户
阅读全文
摘要:A low-privileged authenticated user can call PUT /jshERP-boot/role/update directly to modify shared role template fields such as type and priceLimit, causing batch privilege expansion and business-rule bypass for users bound to that role.
阅读全文
摘要:RuoYi has a missing authorization vulnerability: Role Menu Permission Overwrite. 角色被授予操作者本不具备的菜单/接口权限;若该角色已分配给用户,权限会在 Shiro 重新加载后生效。
阅读全文
摘要:RuoYi has a missing authorization vulnerability: Role Data Scope Escalation. 扩大角色数据权限,使拥有该角色的用户后续通过 DataScope 查询到未授权部门数据。
阅读全文
摘要:RuoYi has a missing authorization vulnerability: Unauthorized Role Assignment To Users. 给不可见用户授予角色,改变其 RBAC membership 和后续权限集合。
阅读全文
摘要:RuoYi has a missing authorization vulnerability: Unauthorized Role Assignment Deletion. 越权撤销目标用户角色,导致权限被移除。
阅读全文
摘要:RuoYi has a missing authorization vulnerability: Department Hierarchy Rebinding. 越权创建或移动部门,改变 DataScope 使用的部门层级授权路径。
阅读全文
摘要:RuoYi has a missing authorization vulnerability: Menu Permission Property Overwrite. 破坏菜单权限资源边界;`perms` 会被 Shiro 作为权限字符串加载,可能使角色权限语义被篡改。
阅读全文
摘要:Ampache has a missing authorization vulnerability: API Direct Share Read. The attacker can read another user's share `secret`, `public_url`, `object_type`, `object_id`, `allow_stream`, and `allow_download`. The `secret` and `public_url` are capability-style access credentials that can be used to consume the share
阅读全文
摘要:Ampache has a missing authorization vulnerability: API Shares List. The attacker can enumerate and retrieve other users' share `secret` and `public_url` values in bulk
阅读全文
摘要:Ampache has a missing authorization vulnerability: API `share_create` Arbitrary Target. The attacker can create a public share for an unauthorized target object. The resulting `share.secret` / `share.public_url` can be used to access the object through the share flow
阅读全文
摘要:Ampache has a missing authorization vulnerability: Web Share Create / External Share Arbitrary Target. The attacker can create a public share for an object they cannot otherwise access
阅读全文
摘要:Ampache has a missing authorization vulnerability: Playlist Source Object Authorization Bypass. The attacker can bind unauthorized source content into their own playlist. That playlist can later be read, played, or shared through flows that trust `playlist_data`
阅读全文
摘要:DSpace has a missing authorization vulnerability: Relationship Creation Allows Unauthorized Author/Profile Binding. Unauthorized `READ` access to another in-progress item through forged author/profile relationship metadata
阅读全文
摘要:DSpace has a missing authorization vulnerability: EPerson byEmail Search Leaks Account Authorization Properties. Unauthorized disclosure of EPerson account attributes including `email`, `netid`, `canLogIn`, `requireCertificate`, `selfRegistered`, and `lastActive`. These are authorization/authentication-related properties, especially `netid` and login flags
阅读全文
摘要:DSpace has a missing authorization vulnerability: Registration Token Path Allows Arbitrary netid Binding. Unauthorized write to `eperson.netid`, an authentication binding property used by external authentication integrations. This can pre-bind an account to an arbitrary unused external identity identifier
阅读全文
摘要:JEEWMS has a missing authorization vulnerability: `saveUser` 可重建用户角色和组织绑定. 可将任意用户加入更高权限角色或跨组织绑定,改变系统后续菜单、接口、数据权限判断结果。
阅读全文
摘要:JEEWMS has a missing authorization vulnerability: `updateAuthority` 可改写角色功能权限. 可给角色授予或移除菜单/功能权限,影响用户后续可访问功能和授权状态。
阅读全文
摘要:JEEWMS has a missing authorization vulnerability: `updateDataRule` 可改写角色数据规则. 可扩大、清空或替换角色在某功能下的数据权限规则,影响后续数据过滤范围。
阅读全文
摘要:JEEWMS has a missing authorization vulnerability: `doAddUserToRole` 可批量添加用户到任意角色. 可将自己或其他用户加入高权限角色,直接提升系统权限。
阅读全文
摘要:JEEWMS has a missing authorization vulnerability: `/rest/user` 暴露用户实体 CRUD. 可绕过正常用户管理流程,修改账号状态、用户类型、删除用户等授权相关状态;部分字段还可能造成账户控制或业务破坏。
阅读全文
摘要:JEEWMS has a missing authorization vulnerability: `/rest/tmsYwDingdanController` 运输订单 REST CRUD 缺少组织 scope. 可绕过正常页面列表的组织范围过滤,跨组织读取或篡改运输订单;`sysOrgCode` 是该业务对象的数据归属边界字段。
阅读全文
摘要:JSH_ERP has a missing authorization vulnerability in `POST /user/resetPwd`. A low-privileged user can reset and take over any non-`admin` account in the same reachable data scope. If the target account has higher business privileges, this becomes privilege escalation and account takeover
阅读全文
摘要:JSH_ERP has a missing authorization vulnerability in `GET /userBusiness/getBasicData`. The endpoint discloses authorization relationships: users' roles, role functions/buttons, warehouse access, and customer access. These relationships are consumed by permission and data-scope logic throughout the application
阅读全文
摘要:JSH_ERP has a missing authorization vulnerability in `POST /userBusiness/add`, `PUT /userBusiness/update`, `DELETE /userBusiness/delete`, `DELETE /userBusiness/deleteBatch`, `POST /userBusiness/updateBtnStr`, `POST /userBusiness/updateOneValueByKeyIdAndType`. A low-privileged user can modify role assignments, menu/function mappings, button permissions, warehouse access, or customer access. This can directly change authorization state and expand the attacker's effective permissions
阅读全文
摘要:JSH_ERP has a missing authorization vulnerability in `POST /user/addUser`, `PUT /user/updateUser`. A low-privileged user can assign a higher role to themselves or others and move users into organizations that affect data visibility and business permissions
阅读全文
摘要:JSH_ERP has a missing authorization vulnerability in `POST /role/add`, `PUT /role/update`, `POST /role/batchSetStatus`, `DELETE /role/delete`, `DELETE /role/deleteBatch`. A user can weaken price masking, change data-scope type, enable disabled roles, or delete roles. This can grant broader business data visibility and alter authorization behavior for all users assigned to the affected role
阅读全文
摘要:JSH_ERP has a missing authorization vulnerability in `POST /function/findMenuByPNumber`. The endpoint discloses another user's effective menu permissions and role-derived function access. This is authorization-state leakage
阅读全文
摘要:JSH_ERP has a missing authorization vulnerability in `GET /role/findUserRole`, `GET /depot/findUserDepot`, `GET /supplier/getUserCustomerValue`, `GET /user/getUserWithChecked`. The endpoints reveal authorization relationships such as which role a user has, which warehouses a user can access, which customers are assigned, or which users are linked to a relationship value
阅读全文
摘要:JSH_ERP has a missing authorization vulnerability in `POST /user/registerUser`. An attacker can self-register a tenant with excessive user quota or an arbitrary future expiration time, bypassing service-side trial and quota controls
阅读全文
摘要:MCMS has a missing authorization vulnerability: Backend category list bypasses `cms:category:view`. Unauthorized backend users can read category hierarchy and metadata, including parent links, display/search flags, model bindings, category flags, and business child markers
阅读全文
摘要:MCMS has a missing authorization vulnerability: Generate module category list bypasses category/generate read permission. Unauthorized backend users can retrieve complete category metadata through the static-generation helper endpoint
阅读全文
摘要:MCMS has a missing authorization vulnerability: `getFromFengMian` bypasses `cms:content:view`. Unauthorized users can read article fields including category relation, display status, type, details, out-link, and hit count
阅读全文
摘要:MCMS has a missing authorization vulnerability: Content copy uses `cms:content:save` to read and clone source content. A save-only user can read and duplicate source article data they are not authorized to view
阅读全文
摘要:MCMS has a missing authorization vulnerability: Public category get bypasses public visibility filters. Public users can retrieve hidden or non-CMS category metadata that the public category list intentionally filters out
阅读全文
摘要:MCMS has a missing authorization vulnerability: `/ms/cms/category/copyCategory`. unauthorized access to authorization-sensitive state
阅读全文
摘要:MicroCommunity has a missing authorization vulnerability: Confirmed Vulnerability. A user with access to this action can bind a high-privilege role to themselves or another staff account, causing privilege escalation across the backend permission system
阅读全文

浙公网安备 33010602011771号