漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Broken Access Control in extension "Frontend User Registration" (sf_register)
Vulnerability Description
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.
CVSS Information
N/A
Vulnerability Type
CWE-915
Vulnerability Title
TYPO3 Extension Frontend User Registration 安全漏洞
Vulnerability Description
TYPO3 Extension Frontend User Registration是TYPO3开源的一个TYPO3前台用户注册扩展。 TYPO3 Extension Frontend User Registration存在安全漏洞,该漏洞源于创建和编辑流程未限制用户属性提交且未对前端用户组分配实施访问控制,可能导致攻击者将任意前端用户组分配给新注册或编辑的账户,从而未经授权访问受限制的内容和功能。
CVSS Information
N/A
Vulnerability Type
N/A