Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Magnolia CE ActivationHandler 权限许可和访问控制漏洞
Vulnerability Description
3.5.4版本以前的Magnolia CE 3.5.x 中的ActivationHandler在输入时并不验证权限许可,这会允许远程攻击者通过一个新项目的激活(可能包括增加任意新内容)造成未知影响。
CVSS Information
N/A
Vulnerability Type
N/A