漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a profile. An attacker with admin account can exploit this issue via blind SQL injection, allowing for the extraction of arbitrary data from the database. The vulnerability arises from insufficient sanitizing on integer parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Itflow 安全漏洞
Vulnerability Description
ITFlow是ITFlow开源的一款客户 IT 文档、票务和计费 ERP 软件。 Itflow 25.06及之前版本存在安全漏洞,该漏洞源于对整数参数role_id清理不足,可能导致SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A