Envira Gallery Lite 1.16.2 之前的版本在其画廊转换 REST 端点中存在一个缺失授权验证的安全漏洞。该漏洞允许具有较低权限的已认证用户在未具备所需权限的情况下创建并发布 Envira 画廊,因为该端点仅检查源帖子的编辑权限,并使用硬编码的发布状态。此外,攻击者还可以提供任意的、由调用者控制的图片 ID,而无需进行所有权验证,从而利用其无权使用的附件发布未经授权的内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Syed Balkhi | Envira Gallery | 0 ~ 1.16.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet