漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Webkul Bagisto Customer Item Deletion Endpoint access control
Vulnerability Description
A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
访问控制不恰当
Vulnerability Title
Webkul Bagisto 权限许可和访问控制问题漏洞
Vulnerability Description
Webkul Bagisto是印度Webkul公司的一款电商系统平台。 Webkul Bagisto 2.4.4及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于Customer Item Deletion Endpoint组件存在访问控制不当,可能导致远程攻击者利用该漏洞影响数据完整性和可用性。
CVSS Information
N/A
Vulnerability Type
N/A