在 QloApps 1.7.0 及之前版本中,AdminHotelRoomsBookingController::postProcess() 方法存在一个授权绕过漏洞。攻击者可以通过提供 参数,使受限制的后台员工能够访问其他酒店的数据。具体来说,攻击者可以在“立即预订”(Book Now)页面修改 URL 参数中的 ,从而查看超出其权限范围的其他酒店的房间可用性和预订状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet