上一页 1 2 3 4 5 6 7 8 ··· 14 下一页
摘要: RuoYi has a missing authorization vulnerability: Department Hierarchy Rebinding. 越权创建或移动部门,改变 DataScope 使用的部门层级授权路径。 阅读全文
posted @ 2026-06-18 12:36 Aibot 阅读(5) 评论(0) 推荐(0)
摘要: RuoYi has a missing authorization vulnerability: Unauthorized Role Assignment Deletion. 越权撤销目标用户角色,导致权限被移除。 阅读全文
posted @ 2026-06-18 12:36 Aibot 阅读(4) 评论(0) 推荐(0)
摘要: RuoYi has a missing authorization vulnerability: Unauthorized Role Assignment To Users. 给不可见用户授予角色,改变其 RBAC membership 和后续权限集合。 阅读全文
posted @ 2026-06-18 12:36 Aibot 阅读(6) 评论(0) 推荐(0)
摘要: RuoYi has a missing authorization vulnerability: Role Data Scope Escalation. 扩大角色数据权限,使拥有该角色的用户后续通过 DataScope 查询到未授权部门数据。 阅读全文
posted @ 2026-06-18 12:35 Aibot 阅读(5) 评论(0) 推荐(0)
摘要: RuoYi has a missing authorization vulnerability: Role Menu Permission Overwrite. 角色被授予操作者本不具备的菜单/接口权限;若该角色已分配给用户,权限会在 Shiro 重新加载后生效。 阅读全文
posted @ 2026-06-18 12:35 Aibot 阅读(11) 评论(0) 推荐(0)
摘要: A low-privileged authenticated user can call PUT /jshERP-boot/role/update directly to modify shared role template fields such as type and priceLimit, causing batch privilege expansion and business-rule bypass for users bound to that role. 阅读全文
posted @ 2026-06-18 11:59 Aibot 阅读(7) 评论(0) 推荐(0)
摘要: Vulnerability call chain1.1 Entry: UserController.updateUserUserController exposes PUT /User/update, and the request body is directly passed without a 阅读全文
posted @ 2026-06-17 21:00 Aibot 阅读(10) 评论(0) 推荐(0)
摘要: 连接 发大水 阅读全文
posted @ 2026-05-12 23:36 Aibot 阅读(9) 评论(0) 推荐(0)
摘要: All Issues illuastrated in this page has been acknowledged by the proj owner Issue 01 — Unauthorized Cross-Project Repository Fork via forkedFromId Ri 阅读全文
posted @ 2026-05-08 14:32 Aibot 阅读(72) 评论(0) 推荐(0)
摘要: Issue 1:role.saveRoleStaff 1. 风险分析(危害分析) 该接口允许直接将角色绑定到任意员工。由于缺少“可授予角色上界”和“可管理用户范围”的限制,攻击者可将高权限角色分配给自己或任意 staff,从而实现权限提升,并被下游鉴权逻辑直接信任,最终导致后台权限体系失控。 2. 阅读全文
posted @ 2026-05-06 16:46 Aibot 阅读(17) 评论(0) 推荐(0)
上一页 1 2 3 4 5 6 7 8 ··· 14 下一页