Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
UserProfile.cs in Ultraapps Issue Manager before 2.1 allows remote authenticated users to gain administrator privileges by modifying the original (1) p_User_user_id and (2) User_user_id parameters to UserProfile.aspx, then modifying the password field.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ultraapps Issue Manager权限升级漏洞
Vulnerability Description
Ultraapps Issue Manager的2.1之前版本中的UserProfile.cs使得远程认证用户可以通过修改到UserProfile.aspx的原(1)p_User_user_id和(2)User_user_id参数,从而修改密码字段而获取管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A