漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unauthorized access to chat contents
Vulnerability Description
A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or channels in other worlds on the same server due to a bug in the reporting feature. The exploitability is limited by the fact that the attacker needs to know the internal channel UUID of the chat channel, which is unlikely to be obtained by an outside attacker, especially for direct messages.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
venueless 安全漏洞
Vulnerability Description
venueless是venueless开源的一个在线活动平台。 Venueless存在安全漏洞,该漏洞源于报告功能存在缺陷,可能导致拥有update world权限的用户泄露同一服务器上其他世界的聊天消息。
CVSS Information
N/A
Vulnerability Type
N/A