Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Azuriom CMS Money Transfer ProfileController.php transferMoney toctou
Vulnerability Description
A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-check time-of-use. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is assessed as difficult. Upgrading to version 1.2.13 is capable of addressing this issue. Patch name: ae5596a9548e010a8a79838806eff60ef9554539. Upgrading the affected component is advised. The vendor was contacted early about this disclosure.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Vulnerability Title
Azuriom 竞争条件问题漏洞
Vulnerability Description
Azuriom是Azuriom组织开源的一个游戏服务器网络解决方案。 Azuriom 1.2.12及之前版本存在竞争条件问题漏洞,该漏洞源于Money Transfer Handler组件中transferMoney函数存在检查时间与使用时间不一致问题(TOCTOU),可能被远程利用导致数据完整性受损。
CVSS Information
N/A
Vulnerability Type
N/A