Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
macrozheng mall Member Endpoint update improper authorization
Vulnerability Description
A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of the file /member/address/update/ of the component Member Endpoint. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
mall 授权问题漏洞
Vulnerability Description
mall是macro个人开发者的一套电商系统,包括前台商城系统及后台管理系统。 macrozheng mall 1.0.3及之前版本存在授权问题漏洞,该漏洞源于对文件/member/address/update/的错误操作,可能导致授权不当。
CVSS Information
N/A
Vulnerability Type
N/A