Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization
Vulnerability Description
A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
waooai waoowaoo 权限许可和访问控制问题漏洞
Vulnerability Description
waooai waoowaoo是waooai团队的一款教育领域的服务器软件。 waooai waoowaoo 0.4.0版本和0.4.1版本存在权限许可和访问控制问题漏洞,该漏洞源于Media Handler组件中函数stablePublicIdFromStorageKey的参数storageKey操作不当,导致授权不当。
CVSS Information
N/A
Vulnerability Type
N/A