iPortalis是提供管理Microsoft 许可证、成本、治理和报告功能。 iPortalis iCS 中存在输入验证错误漏洞,该漏洞源于未对UserRoleKey=请求添加有效的权限认证。攻击者可通过将UserRoleKey=COMPANY ADMIN更改为UserRoleKey=DOMAIN获得域管理权限。 以下产品及版本受到影响:iPortalis iCS 7.1.13.0 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-23427 | 8.6 HIGH | Arbitrary File Write via Archive Extraction (Zip Slip) |
| CVE-2021-23428 | 8.6 HIGH | Directory Traversal |
| CVE-2021-23426 | 5.6 MEDIUM | Prototype Pollution |
| CVE-2021-23436 | 5.6 MEDIUM | Prototype Pollution |
| CVE-2021-23438 | 5.6 MEDIUM | Prototype Pollution |
| CVE-2021-39373 | Samsung H3安全漏洞 | |
| CVE-2021-40350 | Christie Digital DWU850-GS 授权问题漏洞 | |
| CVE-2021-35508 | TeraRecon AQNetClient安全漏洞 | |
| CVE-2021-39379 | Open Solutions For Education openSIS SQL注入漏洞 | |
| CVE-2021-39377 | Open Solutions For Education openSIS SQL注入漏洞 | |
| CVE-2021-40382 | Compro Camera 安全漏洞 | |
| CVE-2021-39378 | Open Solutions For Education openSIS SQL注入漏洞 | |
| CVE-2021-40352 | OpenEMR 日志信息泄露漏洞 | |
| CVE-2021-38703 | KPN Experia WiFi 安全漏洞 | |
| CVE-2020-9000 | iPortalis 资源管理错误漏洞 | |
| CVE-2021-33582 | Cyrus IMAP 加密问题漏洞 | |
| CVE-2021-37415 | ZOHO ManageEngine ServiceDesk Plus 访问控制错误漏洞 | |
| CVE-2021-36235 | Ivanti Workspace Control 授权问题漏洞 | |
| CVE-2021-40353 | Open Solutions For Education openSIS SQL注入漏洞 | |
| CVE-2020-20341 | Yzmcms 代码问题漏洞 |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet