漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
yeqifu warehouse Customer Endpoint CustomerController.java deleteCustomer access control
Vulnerability Description
A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/deleteCustomer of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\CustomerController.java of the component Customer Endpoint. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
访问控制不恰当
Vulnerability Title
warehouse 访问控制错误漏洞
Vulnerability Description
warehouse是yeqifu个人开发者的一个基于spring boot的中小型仓库物流管理系统。 warehouse存在访问控制错误漏洞,该漏洞源于Customer Endpoint组件中文件dataset eposwarehousesrcmainjavacomyeqifuuscontrollerCustomerController.java的函数addCustomer/updateCustomer/deleteCustomer存在访问控制不当问题。
CVSS Information
N/A
Vulnerability Type
N/A