getgrav/grav-plugin-api 插件在 1.0.18 版本之前,在 UsersController.php 的 requireNotSuperTarget() 函数中,未针对七个敏感的用户管理端点强制实施 API 密钥的范围限制。该检查逻辑使用的是当前操作账户的 isSuperAdmin() 方法,而非验证特定 API 密钥是否具备超级管理员权限(通过 isSuperWithinScope() 进行校验)。因此,一个作用范围低于完整超级管理员权限但归属于超级管理员账户的 API 密钥,可能对其他超级
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet