漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action
Vulnerability Description
Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it performs no equivalent authorization check for removals, so submitting an empty `groups` value removes all existing group memberships. Version 5.9.15 contains a patch.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
Craft CMS 安全漏洞
Vulnerability Description
Craft CMS是Craft CMS开源的一套内容管理系统(CMS)。 Craft CMS 5.6.0版本至5.9.14版本存在安全漏洞,该漏洞源于actionSavePermissions端点允许仅具有viewUsers权限的用户从所有用户组中移除任意用户,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A