Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Exposure of Sensitive System Information to an Unauthorized Control Sphere in EasyUse MailHunter Ultimate
Vulnerability Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to obtain the absolute path via unencrypted VIEWSTATE parameter.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Vulnerability Type
将系统数据暴露到未授权控制的范围
Vulnerability Title
EasyUse MailHunter Ultimate 安全漏洞
Vulnerability Description
EasyUse MailHunter Ultimate是中国EasyUse公司的一个准确的电子邮件查找工具。 EasyUse MailHunter Ultimate 2023及之前版本存在安全漏洞,该漏洞源于敏感系统信息暴露给未经授权的Control Sphere,允许经过身份验证的远程用户通过未加密的VIEWSTATE参数获取绝对路径。
CVSS Information
N/A
Vulnerability Type
N/A