Grav API 插件(getgrav/grav-plugin-api)在 1.0.18 版本之前存在一个漏洞。在 BlueprintController 的 injectSecurityTab() 函数中,该插件未正确应用 API 密钥的作用域限制,用于判断页面的安全性/权限蓝图部分是否可编辑。由于该函数直接执行原始的 isSuperAdmin() 或 hasPermission() 检查,且不依赖于请求参数,因此无法强制实施 scopeAllows() 限制。这意味着,拥有受作用域限制的 API 密钥的用户可能
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet