脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and Tampering
脆弱性説明
NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The application has an authorization model that restricts normal users to campaigns they created, but multiple MCP campaign handlers ignore the authenticated user ID and query or mutate campaigns only by object ID. As a result, a low-privileged authenticated user with a valid MCP API token can enumerate all campaigns, read campaign details, update or delete campaigns owned by other users, modify campaign templates and steps, and potentially trigger or pause campaign delivery. Version 0.12.2 fixes the issue.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
脆弱性タイプ
访问控制不恰当
脆弱性タイトル
pdovhomilja nextcrm-app 权限许可和访问控制问题漏洞
脆弱性説明
pdovhomilja nextcrm-app是pdovhomilja个人开发者的一款云计算客户关系管理应用程序。 pdovhomilja nextcrm-app 0.12.1版本存在安全漏洞,该漏洞源于MCP campaign工具忽略用户ID仅通过对象ID查询或修改活动,可能导致拥有有效MCP API令牌的低权限用户枚举所有活动、读取活动详情、更新或删除其他用户的活动、修改活动模板和步骤,以及触发或暂停活动传递。
CVSS情報
N/A
脆弱性タイプ
N/A