Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tovy before v0.7.51 vulnerable to users logging in as and impersonating other users
Vulnerability Description
Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including privileged users such as the other of the instance. The problem has been patched in version 0.7.51.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
Tovy 授权问题漏洞
Vulnerability Description
Tovy是Tovy开源的一个开源员工管理平台。 Tovy 0.7.51之前的版本存在授权问题漏洞,该漏洞源于其允许用户以包括特权用户在内的其他用户的身份登录。
CVSS Information
N/A
Vulnerability Type
N/A