漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
Vulnerability Description
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Typemill 授权问题漏洞
Vulnerability Description
Typemill是Typemill个人开发者开源的一款基于文件的轻量级内容管理系统。 Typemill 2.26.0之前版本存在授权问题漏洞,该漏洞源于媒体文件下载路由的授权绕过问题,攻击者可通过提交路径等效的URL变体(如点斜杠前缀、双斜杠或百分号编码序列)绕过基于角色的限制检查,导致未经身份验证的攻击者未授权下载受保护文件。
CVSS Information
N/A
Vulnerability Type
N/A