在 macrozheng mall 版本 1.0.3 及之前的版本中检测到一处安全漏洞。该漏洞影响组件 Order Submission 中 /order/submit 文件的某个未知功能。该问题由操作引发,导致竞态条件(race condition)。攻击可远程发起,但攻击复杂度较高,且可利用性被认为较为困难。此外,供应商在未给出任何解释的情况下删除了 GitHub 上关于此漏洞的 issue。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| macrozheng | mall | 1.0.0 |
cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet