漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
stoatchat before 0.15.0 Missing Authorization via Subscribe
Vulnerability Description
stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of private servers without membership. Attackers can subscribe to any server's member-update topic by sending a Subscribe message with an arbitrary server ID, receiving live UserUpdate events including display names, avatars, and status changes for members they should not have access to.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
stoatchat 授权问题漏洞
Vulnerability Description
stoatchat是stoatchat组织的一款面向办公自动化场景的服务器端即时通讯平台。 stoatchat 0.15.0之前版本存在授权问题漏洞,该漏洞源于Subscribe消息处理器存在缺失授权问题,允许已认证攻击者通过发送带有任意服务器ID的Subscribe消息订阅任意服务器的成员更新主题,从而枚举成员并监控私有服务器成员的个人资料更新。
CVSS Information
N/A
Vulnerability Type
N/A