Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerability in resetpass.php to modify passwords for arbitrary users.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
openInvoice 'auth.php'身份认证授权绕过漏洞
Vulnerability Description
openInvoice是一个发票管理小工具,可以根据格式要求定制和打印,并通过邮件自动发送给发票被开具者。 openInvoice0.90 beta版本及其早期版本的auth.php允许远程攻击者通过设置oiauth cookie,绕过权限并获得特权。注意:该漏洞可以与resetpass.php中的一个独立漏洞结合,更改任意用户的密码。
CVSS Information
N/A
Vulnerability Type
N/A