Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper Access Control Vulnerability in Wave 2.0
Vulnerability Description
This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.
CVSS Information
N/A
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Brokerage Wave 安全漏洞
Vulnerability Description
Brokerage Wave是Brokerage公司的一个前台产品。 Brokerage Wave 2.0版本存在安全漏洞,该漏洞源于缺少对某些API端点的授权检查,从而远程攻击者可以通过API请求URL操纵参数user_id来导致未经授权的创建、修改和删除属于其他用户帐户的警报。
CVSS Information
N/A
Vulnerability Type
N/A