Xibo 是一个开源的数字标牌平台,包含基于 Web 的内容管理系统和 Windows 显示播放器软件。在 4.4.3 版本之前, 中缺少对权限(Authorization)的校验,导致拥有“模块查看”权限的用户能够查看(而非修改)仅限超级管理员访问的模块设置,并泄露完整的模块实体信息。该漏洞可被任何拥有“模块查看”权限的授权用户利用;该权限默认并不授予非管理员用户。建议用户升级至 4.4.3 版本以修复此问题,升级至修复版本是必要的缓解措施。若无法升级的用户,应从不受信任的用户处撤销相应权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| xibosignage | xibo-cms | < 4.4.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xibosignage | xibo-cms | < 4.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet