在 tsi-coop 的 tsi-dpdp-cms 组件中(版本 ≤ 0.5.0)发现了一个漏洞。该漏洞影响该组件“Bootstrap 初始化端点”中文件 的未知部分。通过操纵相关逻辑会导致认证缺失(missing authentication)问题。此漏洞可被远程触发,且利用方式(Exploit)已公开并可能正被使用。将版本升级至 0.5.1 可缓解该问题,建议升级受影响组件以修复漏洞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tsi-coop | tsi-dpdp-cms | 0.1 |
affected |
0.2 |
affected | ||
0.3 |
affected | ||
0.4 |
affected | ||
0.5.0 |
affected | ||
0.5.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tsi-coop | tsi-dpdp-cms | 0.1 |
cpe:2.3:a:tsi-coop:tsi-dpdp-cms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84841 | 7.3 HIGH | tsi-coop tsi-dpdp-cms client-side enforcement of server-side security |
| CVE-2026-84839 | 5.3 MEDIUM | tsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing authentication |
No comments yet