Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Roundup 信息泄露漏洞
Vulnerability Description
Roundup是一套命令行、Web和电子邮件问题跟踪系统。该系统提供Bug跟踪、客户帮助台和问题管理等功能。 Roundup 1.5.1之前版本的schema.py中存在安全漏洞,该漏洞源于程序没有正确限制默认用户权限中的属性。远程攻击者可通过查看用户详情利用该漏洞获取敏感的用户信息。
CVSS Information
N/A
Vulnerability Type
N/A