Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An access control issue in aleksis/core/util/auth_helpers.py: ClientProtectedResourceMixin of AlekSIS-Core v2.8.1 and below allows attackers to access arbitrary scopes if no allowed scopes are specifically set.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AlekSIS-Core 安全漏洞
Vulnerability Description
AlekSIS-Core是AlekSIS公司的一个学校信息系统。 AlekSIS-Core v2.8.1版本及之前版本存在安全漏洞,该漏洞源于aleksis/core/util/auth_helpers.py 中存在访问控制问题。
CVSS Information
N/A
Vulnerability Type
N/A