Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.4.0), Mendix Applications using Mendix 7 (All versions < V7.23.37), Mendix Applications using Mendix 8 (All versions < V8.18.27), Mendix Applications using Mendix 9 (All versions < V9.24.10). A capture-replay flaw in the platform could have an impact to apps built with the platform, if certain preconditions are met that depend on the app's model and access control design. This could allow authenticated attackers to access or modify objects without proper authorization, or escalate privileges in the context of the vulnerable app.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
使用捕获-重放进行的认证绕过
Vulnerability Title
Siemens Mendix Applications 安全漏洞
Vulnerability Description
Siemens Mendix是德国西门子(Siemens)公司的一套低代码应用程序开发平台。该平台提供应用程序开发、测试、部署和迭代等功能。 Siemens Mendix Applications 多款产品存在安全漏洞,该漏洞源于如果满足某些取决于应用程序模型和访问控制设计的先决条件,平台中的捕获重放缺陷可能会对使用该平台构建的应用程序产生影响。以下产品及版本受到影响:Mendix Applications using Mendix 10, Mendix Applications using Mendix
CVSS Information
N/A
Vulnerability Type
N/A