漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit
Vulnerability Description
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all subsequent code including database operations to execute regardless of session state.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
maxime amini Atlas Livre 授权问题漏洞
Vulnerability Description
maxime amini Atlas Livre是maxime amini个人开发者开源的一个面向书店的电子商务网站。 maxime amini Atlas Livre de0893f及之前版本存在授权问题漏洞,该漏洞源于Espace_admin/controleur/目录下的admin控制器存在不当的访问控制漏洞,允许未经身份验证的攻击者通过发送忽略重定向的原始HTTP请求绕过基于会话的身份验证防护,攻击者可请求带有GET参数(如supp)的控制器端点调用破坏性管理员操作(如删除记录),因为PHP he
CVSS Information
N/A
Vulnerability Type
N/A