Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
Vulnerability Description
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Typemill 授权问题漏洞
Vulnerability Description
Typemill是Typemill个人开发者开源的一款基于文件的轻量级内容管理系统。 Typemill 2.26.0之前版本存在授权问题漏洞,该漏洞源于媒体文件下载路由的授权绕过问题,攻击者可通过提交路径等效的URL变体(如点斜杠前缀、双斜杠或百分号编码序列)绕过基于角色的限制检查,导致未经身份验证的攻击者未授权下载受保护文件。
CVSS Information
N/A
Vulnerability Type
N/A