漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
MineAdmin JWT Token refresh data authenticity
Vulnerability Description
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
对数据真实性的验证不充分
Vulnerability Title
MineAdmin 数据伪造问题漏洞
Vulnerability Description
MineAdmin是MineAdmin开源的一个权限管理系统。 MineAdmin 1.x版本和2.x版本存在数据伪造问题漏洞,该漏洞源于对数据真实性验证不足。
CVSS Information
N/A
Vulnerability Type
N/A