Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delete, or organize messages via a GET request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ushahidi 安全漏洞
Vulnerability Description
Ushahidi Platform 2.5之前版本中的application/libraries/api/MY_Email_Api_Object.php中的email API中存在漏洞,该漏洞源于不需要身份验证。远程攻击者可利用该漏洞通过GET请求列表、删除或组织消息。
CVSS Information
N/A
Vulnerability Type
N/A