Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (RBAC) through dual dependency on frontend menu systems and backend permission tables, without enforcing atomic synchronization between these components. The critical flaw manifests when frontend menu updates (such as privilege revocation) fail to propagate to the backend permission table in real-time, creating a dangerous desynchronization. While users lose access to restricted functions through the web interface (as UI elements properly disappear), the stale permission records still validate unauthorized API requests when accessed directly through tools like Postman. Attackers exploiting this inconsistency can perform privileged operations including but not limited to: creating high-permission user accounts, accessing sensitive data beyond their clearance level, and executing admin-level commands.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
X-SpringBoot 安全漏洞
Vulnerability Description
X-SpringBoot是czx个人开发者的一个轻量级的Java快速开发平台。 X-SpringBoot 6.0版本存在安全漏洞,该漏洞源于前后端权限组件未同步,可能导致权限提升攻击。
CVSS Information
N/A
Vulnerability Type
N/A