Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access control which leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Blog.Admin 安全漏洞
Vulnerability Description
Blog.Admin是ansonzhang个人开发者的一个基于Vue.js的后台权限管理系统。 blog.admin v.8.0及之前版本存在安全漏洞,该漏洞源于getinfobytoken API接口存在访问控制不当,可能导致未经授权方通过有效令牌获取敏感管理员账户信息,威胁系统安全。
CVSS Information
N/A
Vulnerability Type
N/A