漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external courses for other employees, even though they do not have the option to do so in the user interface. To do this, a valid request to create a course simply needs to be modified, so that the current user ID in the "id" parameter is replaced with the ID of another user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sage DPW 安全漏洞
Vulnerability Description
Sage DPW是英国Sage公司的一个人力资源系统。 Sage DPW 2024_12_000之前版本存在安全漏洞,该漏洞源于服务端访问控制缺失,会导致低权限用户越权操作。
CVSS Information
N/A
Vulnerability Type
N/A