Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
TVN-202110009
Vulnerability Description
The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL parameters.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
Aifu 艾富资讯出纳帐务管理系统 安全漏洞
Vulnerability Description
Aifu 艾富资讯出纳帐务管理系统是中国艾富资讯(Aifu)公司的一个管理系统。用于管理账务。 艾富资讯出纳帐务管理系统存在授权问题漏洞,该漏洞源于软件缺少针对工资查询功能的缺陷限制。攻击者可以绕过AIFU出纳管理工资查询功能的权限控制,远程攻击者可利用该漏洞在获得一般用户权限后,通过制作URL参数,即可访问除密码外的账户信息。
CVSS Information
N/A
Vulnerability Type
N/A