Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Uasoft Badaso File API api.php class permission
Vulnerability Description
A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
Permission Issues
Vulnerability Title
Uasoft badaso 权限许可和访问控制问题漏洞
Vulnerability Description
Uasoft badaso是Uasoft组织开源的一个可快速构建后台管理界面的开发框架。 Uasoft badaso 3.0.0-alpha版本存在权限许可和访问控制问题漏洞,该漏洞源于File API组件中ApiRequest::class函数对src/Routes/api.php文件的操作,可能导致权限问题。
CVSS Information
N/A
Vulnerability Type
N/A