InvenTree 是一个开源的库存管理系统。在 1.4.0 版本之前, 接口允许攻击者构造并发送包含小写模型标签(model label)和整数主键(primary key)的内部 JSON 条码数据。同时, 视图仅使用 进行权限校验,意味着只需经过身份验证或拥有通用的读取权限即可访问。 系统内置的条码插件通过 直接获取对应对象,而 方法在未检查调用者对具体模型的视图权限(view role)的情况下,直接返回该模型的完整序列化数据作为实例输出。 因此,一个低权限用户可以枚举部件(parts)、库存(stock)
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61749 | 6.5 MEDIUM | InvenTree: Administrative staff users can trigger Arbitrary File Read leading to Credentia |
| CVE-2026-61746 | 5.3 MEDIUM | InvenTree: Plugin-settings GET endpoints are readable without authentication |
| CVE-2026-61748 | 4.3 MEDIUM | InvenTree: Report/Label print endpoints ignore per-model permissions |
| CVE-2026-61747 | 4.3 MEDIUM | InvenTree: Authenticated IDOR in the data-import API exposes other users' imported rows (` |
| CVE-2026-61745 | 4.3 MEDIUM | InvenTree: Missing authorization on machine restart endpoint allows any authenticated user |
No comments yet