在 dotnet eShop .NET 8 中发现了一个安全漏洞。受影响的是 Ordering API 组件中文件 src/Ordering.API/Apis/OrdersApi.cs 的 GetOrderAsync 函数。对参数 OrderNumber 进行操作会导致资源标识符控制不当。该攻击可以远程执行。该项目已通过问题报告尽早得知此问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet