Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
Vulnerability Description
Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers can enumerate room IDs via the rooms listing endpoint and permanently archive private or password-protected rooms they cannot access, with no application-level recovery path requiring direct database intervention to restore.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
授权机制缺失
Vulnerability Title
sdelements lets-chat 授权问题漏洞
Vulnerability Description
sdelements lets-chat是sdelements个人开发者开源的一个团队协作聊天软件。 sdelements lets-chat 0.3.0版本至0.4.8版本存在授权问题漏洞,该漏洞源于授权不当,允许任何经过身份验证的用户在无所有权验证的情况下向rooms handler发送DELETE请求归档服务器上的任意房间,攻击者可通过rooms listing端点枚举房间ID并永久归档私有或受密码保护的房间,且无应用级恢复路径。
CVSS Information
N/A
Vulnerability Type
N/A