Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Missing Authorization vulnerability in CanalDenuncia.app
Vulnerability Description
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in '/api/buscarEmpresaById.php'.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
CanalDenuncia App 安全漏洞
Vulnerability Description
CanalDenuncia App是西班牙CanalDenuncia公司的一个举报通道应用软件。 CanalDenuncia App存在安全漏洞,该漏洞源于缺少授权检查,攻击者可通过向/api/buscarEmpresaById.php发送包含参数id和id_sociedad的POST请求访问其他用户信息。
CVSS Information
N/A
Vulnerability Type
N/A