Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The canUpdate function in model/MRole.java in Adempiere before 3.1.6 does not properly validate user roles, which allows remote authenticated read-only users to gain read-write privileges. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Adempiere 'MRole.java' 漏洞
Vulnerability Description
Adempiere 的model/MRole.java中的canUpdate函数没有正确的校验用户角色,这使得远程认证只读取用户可以获得特权。
CVSS Information
N/A
Vulnerability Type
N/A