OneNav是使用PHP开发的简约导航/书签管理系统。 OneNav 0.9.33版本及之前版本存在授权问题漏洞,该漏洞源于对参数 X-Token 的错误操作会导致身份验证不正确。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | OneNav | 0.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-7212 | 4.7 MEDIUM | DeDeCMS Backend file_class.php unrestricted upload |
| CVE-2024-0262 | 2.4 LOW | Online Job Portal Create News Page News.php cross site scripting |
No comments yet