漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and exploiting the 'file' parameter. By referencing specific files (e.g., cm3.xml), attackers can bypass access controls, leading to account takeover and potential privilege escalation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DDSN Interactive cm3 Acora CMS 安全漏洞
Vulnerability Description
DDSN Interactive cm3 Acora CMS是DDSN Interactive公司的一个企业网络和移动 CMS。 DDSN Interactive cm3 Acora CMS 10.1.1版本存在安全漏洞,该漏洞源于存在不正确的权限改造漏洞,会导致帐户接管和潜在的权限提升。
CVSS Information
N/A
Vulnerability Type
N/A