Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Group-Office before 2.16-13 does not properly validate user IDs, which allows remote attackers to obtain sensitive information via certain requests for (1) message.php and (2) messages.php in modules/email/. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Group-Office 多个安全绕过漏洞
Vulnerability Description
Group-Office 没有正确的验证用户IDs,这使得远程攻击者可以借助对modules/email/中的(1)message.php和(2)messages.php文件的特定请求,获得敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A