漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
dulaiduwang003 TIME-SEA-PLUS Order Status PayController.java alipayIsSucceed improper authorization
Vulnerability Description
A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affects the function alipayIsSucceed of the file PayController.java of the component Order Status Handler. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
TIME-SEA-PLUS 授权问题漏洞
Vulnerability Description
TIME-SEA-PLUS是bdth个人开发者的一个Ai平台。 dulaiduwang003 TIME-SEA-PLUS存在授权问题漏洞,该漏洞源于文件PayController.java中函数alipayIsSucceed存在授权不当,可能导致远程攻击。
CVSS Information
N/A
Vulnerability Type
N/A