Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote attackers to conduct unauthorized sort operations and other activities.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lussumo Vanilla 权限许可和访问控制漏洞
Vulnerability Description
Lussumo Vanilla 1.1.3版本及其早期版本没有要求管理特权,这些管理特权对应(1) ajax/sortcategories.php 和 (2) ajax/sortroles.php, 这会允许远程攻击者执行未授权操作和其他活动。
CVSS Information
N/A
Vulnerability Type
N/A