漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
RafyMrX TOKO-ONLINE-ROTI add.php authorization
Vulnerability Description
A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument kd_cs leads to authorization bypass. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Ahmad Rafi Akbar Putra Hamzah Toko Online Roti 授权问题漏洞
Vulnerability Description
Ahmad Rafi Akbar Putra Hamzah Toko Online Roti是Ahmad Rafi Akbar Putra Hamzah个人开发者的一个在线面包店管理平台,支持制造流程与后台管理。 Ahmad Rafi Akbar Putra Hamzah Toko Online Roti存在授权问题漏洞,该漏洞源于文件proses/add.php中参数kd_cs存在授权绕过,可能导致远程攻击。
CVSS Information
N/A
Vulnerability Type
N/A