在 Phproject 1.8.7 之前的版本中,REST API 的工单(issue)端点(包括 single_get、single_comments 和 single_comments_post)存在缺失的对象级授权漏洞。该漏洞允许持有有效 API 密钥的已认证用户绕过 security.restrict_access 的机密性控制,因为系统从未调用 allowAccess() 授权例程。攻击者可以利用合法的 API 密钥读取受限制的工单内容及其评论,包括工单所有者和作者电子邮件地址,并且可以向无权访问的工单发
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Alanaktion | phproject | 1.1.6< 1.8.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Alanaktion | phproject | 1.1.6 ~ 1.8.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet