漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
Vulnerability Description
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 and 2.41.1 contain a patch.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
OpenSource-WorkShop Connect-CMS 安全漏洞
Vulnerability Description
OpenSource-WorkShop Connect-CMS是日本OpenSource-WorkShop公司的一个用于轻松创建网站的内容管理系统。 Connect-CMS 1.41.0及之前版本和2.41.0及之前版本存在安全漏洞,该漏洞源于我的页面配置文件更新功能存在授权不当问题,可能导致修改任意用户信息。
CVSS Information
N/A
Vulnerability Type
N/A