漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Azuriom CMS Money Transfer ProfileController.php transferMoney toctou
Vulnerability Description
A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-check time-of-use. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is assessed as difficult. Upgrading to version 1.2.13 is capable of addressing this issue. Patch name: ae5596a9548e010a8a79838806eff60ef9554539. Upgrading the affected component is advised. The vendor was contacted early about this disclosure.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Vulnerability Title
Azuriom 竞争条件问题漏洞
Vulnerability Description
Azuriom是Azuriom组织开源的一个游戏服务器网络解决方案。 Azuriom 1.2.12及之前版本存在竞争条件问题漏洞,该漏洞源于Money Transfer Handler组件中transferMoney函数存在检查时间与使用时间不一致问题(TOCTOU),可能被远程利用导致数据完整性受损。
CVSS Information
N/A
Vulnerability Type
N/A