上一页 1 2 3 4 5 6 ··· 14 下一页
摘要: JSH_ERP has a missing authorization vulnerability in `POST /role/add`, `PUT /role/update`, `POST /role/batchSetStatus`, `DELETE /role/delete`, `DELETE /role/deleteBatch`. A user can weaken price masking, change data-scope type, enable disabled roles, or delete roles. This can grant broader business data visibility and alter authorization behavior for all users assigned to the affected role 阅读全文
posted @ 2026-06-18 12:39 Aibot 阅读(4) 评论(0) 推荐(0)
摘要: JSH_ERP has a missing authorization vulnerability in `POST /user/addUser`, `PUT /user/updateUser`. A low-privileged user can assign a higher role to themselves or others and move users into organizations that affect data visibility and business permissions 阅读全文
posted @ 2026-06-18 12:38 Aibot 阅读(5) 评论(0) 推荐(0)
摘要: JSH_ERP has a missing authorization vulnerability in `POST /userBusiness/add`, `PUT /userBusiness/update`, `DELETE /userBusiness/delete`, `DELETE /userBusiness/deleteBatch`, `POST /userBusiness/updateBtnStr`, `POST /userBusiness/updateOneValueByKeyIdAndType`. A low-privileged user can modify role assignments, menu/function mappings, button permissions, warehouse access, or customer access. This can directly change authorization state and expand the attacker's effective permissions 阅读全文
posted @ 2026-06-18 12:38 Aibot 阅读(3) 评论(0) 推荐(0)
摘要: JSH_ERP has a missing authorization vulnerability in `GET /userBusiness/getBasicData`. The endpoint discloses authorization relationships: users' roles, role functions/buttons, warehouse access, and customer access. These relationships are consumed by permission and data-scope logic throughout the application 阅读全文
posted @ 2026-06-18 12:38 Aibot 阅读(4) 评论(0) 推荐(0)
摘要: JSH_ERP has a missing authorization vulnerability in `POST /user/resetPwd`. A low-privileged user can reset and take over any non-`admin` account in the same reachable data scope. If the target account has higher business privileges, this becomes privilege escalation and account takeover 阅读全文
posted @ 2026-06-18 12:38 Aibot 阅读(4) 评论(0) 推荐(0)
摘要: JEEWMS has a missing authorization vulnerability: `/rest/tmsYwDingdanController` 运输订单 REST CRUD 缺少组织 scope. 可绕过正常页面列表的组织范围过滤,跨组织读取或篡改运输订单;`sysOrgCode` 是该业务对象的数据归属边界字段。 阅读全文
posted @ 2026-06-18 12:38 Aibot 阅读(5) 评论(0) 推荐(0)
摘要: JEEWMS has a missing authorization vulnerability: `/rest/user` 暴露用户实体 CRUD. 可绕过正常用户管理流程,修改账号状态、用户类型、删除用户等授权相关状态;部分字段还可能造成账户控制或业务破坏。 阅读全文
posted @ 2026-06-18 12:38 Aibot 阅读(4) 评论(0) 推荐(0)
摘要: JEEWMS has a missing authorization vulnerability: `doAddUserToRole` 可批量添加用户到任意角色. 可将自己或其他用户加入高权限角色,直接提升系统权限。 阅读全文
posted @ 2026-06-18 12:38 Aibot 阅读(5) 评论(0) 推荐(0)
摘要: JEEWMS has a missing authorization vulnerability: `updateDataRule` 可改写角色数据规则. 可扩大、清空或替换角色在某功能下的数据权限规则,影响后续数据过滤范围。 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(4) 评论(0) 推荐(0)
摘要: JEEWMS has a missing authorization vulnerability: `updateAuthority` 可改写角色功能权限. 可给角色授予或移除菜单/功能权限,影响用户后续可访问功能和授权状态。 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(3) 评论(0) 推荐(0)
上一页 1 2 3 4 5 6 ··· 14 下一页