漏洞描述翻译: starlette-admin 版本 0.16.1 至 0.17.1 在将 配置为空列表时,未能强制应用该白名单机制,导致已认证用户能够对不可搜索的字段进行过滤操作。攻击者可以通过列表 API 的 参数提交结构化的过滤查询,从而对被排除的列执行等值及比较运算。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jowilf | starlette-admin | 0.16.1 ~ 0.17.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet