漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WBCE CMS is Vulnerable to Privilege Escalation via Group ID Manipulation (IDOR)
Vulnerability Description
WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by manipulating the groups[] parameter in the /admin/users/save.php request. The UI restricts users to assigning only their existing group, but server-side validation is missing, allowing attackers to overwrite their group membership and obtain full administrative access. This results in a complete compromise of the CMS. This issue has been patched in version 1.6.4.
CVSS Information
N/A
Vulnerability Type
特权授予不正确
Vulnerability Title
WBCE CMS 授权问题漏洞
Vulnerability Description
WBCE CMS是WBCE CMS开源的一套基于PHP和MySQL的开源内容管理系统(CMS)。 WBCE CMS 1.6.4之前版本存在授权问题漏洞,该漏洞源于低权限用户可通过操纵/admin/users/save.php请求中的groups[]参数提升权限至管理员组,导致完全控制CMS。
CVSS Information
N/A
Vulnerability Type
N/A