Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates
Vulnerability Description
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check either, allowing an unauthenticated attacker to read, overwrite, deactivate, and permanently delete any boilerplate template in the system. This vulnerability is fixed in 1.8.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Faction 访问控制错误漏洞
Vulnerability Description
Faction是Faction Security开源的一个笔检报告生成和评估协作框架。 Faction 1.8.3之前版本存在访问控制错误漏洞,该漏洞源于AccessControlInterceptor无条件调用invocation.invoke()而未检查有效会话,可能导致未经身份验证的攻击者读取、覆盖、停用和永久删除任何样板模板。
CVSS Information
N/A
Vulnerability Type
N/A