在 ChangeWeDer crm 中(截至 commit c07bd4c97141521af6475034bc58523beed51bbd)发现一个安全漏洞。该漏洞影响函数 。由于对该函数的不当操作会导致认证机制失效(improper authentication)。攻击者可远程发起攻击。由于该产品采用持续交付(Continuous Delivery)和滚动发布(rolling releases)模式,因此没有具体的受影响版本或已修复版本的详细信息。项目组已通过问题报告提前获知此问题,但截至目前尚未做出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ChangeWeDer | crm | c07bd4c97141521af6475034bc58523beed51bbd |
cpe:2.3:a:changeweder:crm:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92402 | 6.3 MEDIUM | ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index author |
| CVE-2026-92418 | 3.5 LOW | ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting |
No comments yet