Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Modoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change API
Vulnerability Description
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain admin privileges can bypass object-level access controls to reset superadmin passwords and achieve full account takeover.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Modoboa 授权问题漏洞
Vulnerability Description
Modoboa是Modoboa团队开源的一个邮件托管和管理平台。 Modoboa 2.9.0之前版本存在授权问题漏洞,该漏洞源于PUT /api/v1/accounts/{pk}/password/端点中存在不安全的直接对象引用,允许域管理员更改任何用户的密码,攻击者可通过域管理员权限绕过对象级访问控制重置超级管理员密码,实现完全账户接管。
CVSS Information
N/A
Vulnerability Type
N/A