漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unauthorized Modification of Ticket Requester
Vulnerability Description
A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy. The ticket requester can be changed from the original requester to another user in the same application, which the application then accepts.
CVSS Information
N/A
Vulnerability Type
对假设不可变Web参数的外部可控制
Vulnerability Title
Issuetrak 安全漏洞
Vulnerability Description
Issuetrak是Issuetrak公司的一个问题跟踪软件。 Issuetrak 17.1版本存在安全漏洞,该漏洞源于存在隐藏字段操纵漏洞,经过身份验证的用户提交工单时,该请求可能会被拦截,随后使用代理进行修改。
CVSS Information
N/A
Vulnerability Type
N/A