Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
NextCRM has Broken Access Control in Server Actions that allows any authenticated user to deactivate/activate arbitrary accounts
Vulnerability Description
NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js Server Actions of NextCRM. The application fails to verify if the requesting user holds the `admin` role. Consequently, any authenticated user (even those with the lowest `member` or `viewer` roles) can arbitrarily activate or deactivate any user account in the system, including the main administrator. Version 0.12.0 fixes the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
授权机制缺失
Vulnerability Title
pdovhomilja nextcrm-app 授权问题漏洞
Vulnerability Description
pdovhomilja nextcrm-app是pdovhomilja个人开发者的一款云计算客户关系管理应用程序。 pdovhomilja nextcrm-app 0.12.0之前版本存在授权问题漏洞,该漏洞源于activateUser和deactivateUser的Next.js Server Actions中存在访问控制缺陷,导致应用未能验证请求用户是否拥有admin角色,任何认证用户可随意激活或停用系统内任何用户账户。
CVSS Information
N/A
Vulnerability Type
N/A