漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with higher privileges. By manipulating the article ID parameter during the duplicate-and-save workflow in textpattern/include/txp_article.php, an attacker can bypass authorization checks and overwrite content belonging to other users.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Textpattern CMS 安全漏洞
Vulnerability Description
Textpattern CMS是Textpattern团队的一个基于Php的内容管理系统。 Textpattern CMS 4.9.0版本存在安全漏洞,该漏洞源于文章管理系统存在访问控制缺陷,可能导致低权限认证用户通过操纵文章ID参数修改高权限用户的文章。
CVSS Information
N/A
Vulnerability Type
N/A