在 ChangeWeDer crm(截至提交 c07bd4c97141521af6475034bc58523beed51bbd)中发现了一个安全漏洞。该问题位于组件 top.upstudy.crm.controller.UserController 中 UserController.java 文件的 index 函数。通过对该函数的操作可导致缺少授权检查(缺失认证/授权)。该攻击可远程发起。该产品不使用版本号管理,因此无法提供受影响版本和未受影响版本的具体信息。项目组已通过问题报告提前得知此漏洞,但截至目前尚未作出
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ChangeWeDer | crm | c07bd4c97141521af6475034bc58523beed51bbd |
cpe:2.3:a:changeweder:crm:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92401 | 7.3 HIGH | ChangeWeDer crm improper authentication |
| CVE-2026-92418 | 3.5 LOW | ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting |
No comments yet