这段文字描述了一个针对 Piccolo Admin(基于 Python 的 Piccolo 框架的管理界面和内容管理系统)的漏洞。以下是该漏洞描述的中文翻译: 中文翻译: Piccolo Admin 是一个为 Python 构建的管理界面和内容管理系统,基于 Piccolo 框架。在 1.14.0 版本之前, 使用 来阻止非超级用户发起的 PUT、PATCH、DELETE 和 POST 请求,但允许 GET 请求访问已配置的用户(User)和会话(Session)数据表。与此同时, 暴露了 ,因为该 token 列
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| piccolo-orm | piccolo_admin | < 1.14.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| piccolo-orm | piccolo_admin | < 1.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet