LimeSurvey 社区版 7.0.5 在“调查菜单项创建”接口中存在一个经过身份验证的不当授权(improper authorization)漏洞。 具体而言,仅拥有“全局设置:读取(global settings:read)”权限的已认证用户,可以直接调用 接口创建新的调查菜单项,而无需具备本应要求的“设置:更新(settings:update)”权限。此外,该接口还允许攻击者提交那些在正常界面和预期更新流程中已被限制为非超级管理员可用的菜单 ID,从而实现对管理导航记录的未授权修改。 此问题影响范围:Lim
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LimeSurvey | LimeSurvey | 7.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet