漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
shsuishang ShopSuite ModulithShop JwtAuthenticationFilter.java JwtAuthenticationFilter path traversal
Vulnerability Description
A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impacted is the function JwtAuthenticationFilter of the file src/main/java/com/suisung/shopsuite/common/security/JwtAuthenticationFilter.java. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
ModulithShop 路径遍历漏洞
Vulnerability Description
ModulithShop是Shopsuite个人开发者的一个在线商城系统。 ModulithShop存在路径遍历漏洞,该漏洞源于对文件src/main/java/com/suisung/shopsuite/common/security/JwtAuthenticationFilter.java中函数JwtAuthenticationFilter的错误操作,可能导致路径遍历攻击。
CVSS Information
N/A
Vulnerability Type
N/A