Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Open-School Community Edition 信息泄露漏洞
Vulnerability Description
Open-School是一套基于Web的学校管理软件。该软件提供在线收费、考勤和在线图书馆等功能。Open-School Community Edition是Open-School的社区版。 Open-School Community Edition 2.2版本中存在安全漏洞。远程攻击者可借助‘r’参数(将值导出到index.php)利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A