在 lenve vhr 1.0-SNAPSHOT 中检测到一项安全漏洞。该问题影响 文件中 函数的行为。对参数 的不当操作会导致权限管理不当。该攻击可远程触发。此漏洞的利用方式已公开披露,因此可能被利用。厂商已就此披露提前获得通知,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90498 | 7.3 HIGH | lenve vhr vhr.sql default credentials |
| CVE-2026-90490 | 6.3 MEDIUM | lenve vhr MailReceiver deserialization |
| CVE-2026-90500 | 6.3 MEDIUM | lenve vhr Avatar Upload userface FastDFSUtils.upload unrestricted upload |
| CVE-2026-90499 | 5.4 MEDIUM | lenve vhr Password Update pass HrInfoController.updatePass improper authorization |
No comments yet