漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WeGIA < 3.9.2 Insecure Direct Object Reference via profile_funcionario.php
Vulnerability Description
WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extraction function that overwrites the session-derived identifier. Attackers can enumerate all user identifiers to retrieve full profile data for any employee account, including name, CPF, address, contact details, and administrative flags.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
LabRedesCefetRJ WeGIA 授权问题漏洞
Vulnerability Description
LabRedesCefetRJ WeGIA是LabRedesCefetRJ组织的一款整合文件管理与其他企业应用的软件。 LabRedesCefetRJ WeGIA 3.9.2之前版本存在授权问题漏洞,该漏洞源于员工资料页面存在不安全的直接对象引用,已认证攻击者可通过请求提取函数注入id_pessoa参数以覆盖会话派生标识符,从而访问任意员工记录,可能导致攻击者枚举所有用户标识,获取包括姓名、CPF、地址、联系方式和管理员标志在内的完整个人资料。
CVSS Information
N/A
Vulnerability Type
N/A