Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their privileges. By sending a specially crafted HTTP request, a low-privilege user can access and modify the profile data of any other user, including administrators.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
N/A
Vulnerability Title
ZwiiCMS 安全漏洞
Vulnerability Description
ZwiiCMS是Fred个人开发者的一个建站软件。 ZwiiCMS 13.6.07及之前版本存在安全漏洞,该漏洞源于用户管理组件访问控制不当,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A