在 WeGIA 3.9.2 之前的版本中,密码更改流程存在一个权限绕过漏洞,允许任何已认证用户无需提供现有凭据即可更改其账户密码。该漏洞是通过利用 中对 方法无条件排除在权限检查之外而实现的。攻击者可以通过操纵 参数指向 ,从而通过 而非 进行路由,以绕过当前密码验证,并将临时会话访问权限转化为永久的账户接管。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| LabRedesCefetRJ | WeGIA | < 3.9.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LabRedesCefetRJ | WeGIA | 0 ~ 3.9.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet