漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
blueprintUE: Authenticated Password Change Does Not Verify Current Password
Vulnerability Description
blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit/ does not include a current_password field and does not verify the user's existing password before accepting a new one. Any attacker who obtains a valid authenticated session — through XSS exploitation, session sidejacking over HTTP, physical access to a logged-in browser, or a stolen "remember me" cookie — can immediately change the account password without knowing the original credential, resulting in permanent account takeover. This vulnerability is fixed in 4.2.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
未经验证的口令修改
Vulnerability Title
blueprintUE self-hosted edition 安全漏洞
Vulnerability Description
blueprintUE self-hosted edition是blueprintUE开源的一个自托管的数据建模与可视化工具。 blueprintUE self-hosted edition 4.2.0之前版本存在安全漏洞,该漏洞源于/profile/{slug}/edit/处的密码更改表单不包含current_password字段,且在接受新密码之前不验证用户的现有密码,可能导致获得有效认证会话的攻击者无需知道原始凭据即可立即更改帐户密码,导致永久帐户接管。
CVSS Information
N/A
Vulnerability Type
N/A