Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Shipwire API module 7.x-1.x before 7.x-1.03 for Drupal does not check the view permission for the shipments overview (admin/shipwire/shipments), which allows remote attackers to obtain sensitive information via a request to the page.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal Shipwire API模块安全漏洞
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。Shipwire API是其中的一个负责与Shipwire航运通信服务的模块。 Drupal Shipwire API模块7.x-1.03之前7.x-1.x版本中存在安全漏洞,该漏洞源于程序没有检查shipments概述的‘view’权限。远程攻击者可通过向页面发送请求利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A