Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password screen. Thus, requiring the admin to enter an Old Password value on the Change Password screen does not enhance security. This is problematic in conjunction with XSS.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Serpico 安全漏洞
Vulnerability Description
Serpico 1.3.0版本中存在安全漏洞。攻击者可利用该漏洞无需提供当前密码便可更改密码。
CVSS Information
N/A
Vulnerability Type
N/A