漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Wagtail: Improper permission handling in image preview
Vulnerability Description
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object itself is not exposed. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
不充分权限或特权的处理不恰当
Vulnerability Title
Wagtail 权限许可和访问控制问题漏洞
Vulnerability Description
Wagtail wagtail是Wagtail组织的内容管理系统。 Wagtail存在权限许可和访问控制问题漏洞,该漏洞源于图像预览端点缺少权限检查,可能导致具有Wagtail管理员访问权限的用户预览任意图像。
CVSS Information
N/A
Vulnerability Type
N/A