上一页 1 2 3 4 5 6 7 ··· 14 下一页
摘要: JEEWMS has a missing authorization vulnerability: `saveUser` 可重建用户角色和组织绑定. 可将任意用户加入更高权限角色或跨组织绑定,改变系统后续菜单、接口、数据权限判断结果。 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(4) 评论(0) 推荐(0)
摘要: DSpace has a missing authorization vulnerability: Registration Token Path Allows Arbitrary netid Binding. Unauthorized write to `eperson.netid`, an authentication binding property used by external authentication integrations. This can pre-bind an account to an arbitrary unused external identity identifier 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(4) 评论(0) 推荐(0)
摘要: DSpace has a missing authorization vulnerability: EPerson byEmail Search Leaks Account Authorization Properties. Unauthorized disclosure of EPerson account attributes including `email`, `netid`, `canLogIn`, `requireCertificate`, `selfRegistered`, and `lastActive`. These are authorization/authentication-related properties, especially `netid` and login flags 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(3) 评论(0) 推荐(0)
摘要: DSpace has a missing authorization vulnerability: Relationship Creation Allows Unauthorized Author/Profile Binding. Unauthorized `READ` access to another in-progress item through forged author/profile relationship metadata 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(2) 评论(0) 推荐(0)
摘要: Ampache has a missing authorization vulnerability: Playlist Source Object Authorization Bypass. The attacker can bind unauthorized source content into their own playlist. That playlist can later be read, played, or shared through flows that trust `playlist_data` 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(2) 评论(0) 推荐(0)
摘要: Ampache has a missing authorization vulnerability: Web Share Create / External Share Arbitrary Target. The attacker can create a public share for an object they cannot otherwise access 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(4) 评论(0) 推荐(0)
摘要: Ampache has a missing authorization vulnerability: API `share_create` Arbitrary Target. The attacker can create a public share for an unauthorized target object. The resulting `share.secret` / `share.public_url` can be used to access the object through the share flow 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(3) 评论(0) 推荐(0)
摘要: Ampache has a missing authorization vulnerability: API Shares List. The attacker can enumerate and retrieve other users' share `secret` and `public_url` values in bulk 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(4) 评论(0) 推荐(0)
摘要: Ampache has a missing authorization vulnerability: API Direct Share Read. The attacker can read another user's share `secret`, `public_url`, `object_type`, `object_id`, `allow_stream`, and `allow_download`. The `secret` and `public_url` are capability-style access credentials that can be used to consume the share 阅读全文
posted @ 2026-06-18 12:37 Aibot 阅读(5) 评论(0) 推荐(0)
摘要: RuoYi has a missing authorization vulnerability: Menu Permission Property Overwrite. 破坏菜单权限资源边界;`perms` 会被 Shiro 作为权限字符串加载,可能使角色权限语义被篡改。 阅读全文
posted @ 2026-06-18 12:36 Aibot 阅读(4) 评论(0) 推荐(0)
上一页 1 2 3 4 5 6 7 ··· 14 下一页