zlt2000 microservices-platform 6.0.0 版本之前的版本中,file-center 模块的 DELETE /files/{id} 端点存在授权绕过漏洞,该端点未执行所有权验证。经过身份验证的攻击者可以通过 GET /files 枚举文件标识符,并向删除端点提供这些标识符,从而删除任意用户的文件和元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zlt2000 | microservices-platform | 0 ~ 6.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92466 | 8.8 HIGH | microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Che |
| CVE-2026-92467 | 8.3 HIGH | microservices-platform through 6.0.0 Unverified Password Change via /users/password |
| CVE-2026-92468 | 6.5 MEDIUM | microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via search-center |
No comments yet