Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Beego 访问控制错误漏洞
Vulnerability Description
Beego是一款基于Go语言的开源Web框架。 Beego 存在访问控制错误漏洞,攻击者利用该漏洞可以绕过访问控制。以下产品和版本受到影响:1.12.4 版本及之前版本、2.0.2 之前的 2.x 版本。
CVSS Information
N/A
Vulnerability Type
N/A