Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenAsset Digital Asset Management 输入验证错误漏洞
Vulnerability Description
Openasset是英国Openasset公司的一个为建站行业提供数字资产管理的软件。 OpenAsset Digital Asset Management 存在输入验证错误漏洞,该漏洞允许攻击者在报头中使用x - forward - for指令欺骗它。通过提供诸如127.0.0.1这样的本地主机地址,攻击者可以有效地绕过为该软件配置的所有基于IP地址的访问控制。
CVSS Information
N/A
Vulnerability Type
N/A