漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Magento Commerce Improper Authorization Vulnerability Could Lead To Remote Code Execution
Vulnerability Description
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An attacker with admin privileges could leverage this vulnerability to achieve remote code execution.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
授权机制不恰当
Vulnerability Title
Magento Commerce 安全漏洞
Vulnerability Description
Magento Commerce是提供一流的购物体验,而无需开发人员的支持。 Magento Commerce存在安全漏洞,该漏洞存在的原因是授权检查不足。远程管理员可以绕过实现的安全限制,获得对应用程序的未授权访问。该漏洞允许远程用户绕过授权检查。
CVSS Information
N/A
Vulnerability Type
N/A