漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WeKan Custom Translation translationBody.js setCreateTranslation improper authorization
Vulnerability Description
A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper authorization. The attack can be launched remotely. Upgrading to version 8.19 is sufficient to fix this issue. The patch is identified as f244a43771f6ebf40218b83b9f46dba6b940d7de. It is suggested to upgrade the affected component.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
授权机制不恰当
Vulnerability Title
WeKan 授权问题漏洞
Vulnerability Description
WeKan是WeKan开源的一个看板应用程序。 WeKan 8.18及之前版本存在授权问题漏洞,该漏洞源于对组件Custom Translation Handler的文件client/components/settings/translationBody.js中函数setCreateTranslation操作不当,可能导致授权不当。
CVSS Information
N/A
Vulnerability Type
N/A