Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
youlaitech youlai-mall OrderController.java submitOrderPayment improper authorization
Vulnerability Description
A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPayment of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java. Such manipulation of the argument orderSn leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
youlai-mall 授权问题漏洞
Vulnerability Description
youlai-mall是youlaitech开源的一个全栈商城系统。 youlai-mall 1.0.0版本和2.0.0版本存在授权问题漏洞,该漏洞源于文件mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java中函数submitOrderPayment对参数orderSn的错误操作导致授权不当。
CVSS Information
N/A
Vulnerability Type
N/A