Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
DayByDay CRM - Missing Authorization when Changing Password
Vulnerability Description
In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
授权机制缺失
Vulnerability Title
DayByDay CRM 授权问题漏洞
Vulnerability Description
Bottelet Daybyday Crm是Bottelet个人开发者的一个用于任务、时间、员工、休假管理的建站系统。 DayByDay CRM 中存在授权问题漏洞,该漏洞源于产品允许启动更新用户权限的用户修改任意用户的密码。以下产品及版本受到影响:DayByDay CRM 2.2.0 版本。
CVSS Information
N/A
Vulnerability Type
N/A