Anchor CMS 版本 0.12.7 及之前版本在管理员用户管理接口中未能强制执行基于角色的访问控制(RBAC),使得任何已认证的低权限用户均能创建管理员账户或修改现有管理员账户。拥有“编辑”或“普通用户”角色的攻击者可以直接向 或 接口发送 POST 请求,从而创建新的管理员账户或修改现有管理员的密码,进而获得完整的管理员权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| anchorcms | Anchor CMS | 0 ~ 0.12.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet