Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
stoatchat before 0.15.0 Missing Authorization via Subscribe
Vulnerability Description
stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of private servers without membership. Attackers can subscribe to any server's member-update topic by sending a Subscribe message with an arbitrary server ID, receiving live UserUpdate events including display names, avatars, and status changes for members they should not have access to.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
stoatchat 授权问题漏洞
Vulnerability Description
stoatchat是stoatchat组织的一款面向办公自动化场景的服务器端即时通讯平台。 stoatchat 0.15.0之前版本存在授权问题漏洞,该漏洞源于Subscribe消息处理器存在缺失授权问题,允许已认证攻击者通过发送带有任意服务器ID的Subscribe消息订阅任意服务器的成员更新主题,从而枚举成员并监控私有服务器成员的个人资料更新。
CVSS Information
N/A
Vulnerability Type
N/A