ContiNew Admin(版本 4.1.0 及以下)中的个人消息删除接口存在授权绕过漏洞,使得已认证用户能够删除其他用户的消息和公告。攻击者可以在 参数中提供任意消息标识符,从而删除任意消息记录,并清除所有接收方的已读回执,且系统未进行所有权验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| continew-org | continew-admin | 0 ~ 4.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet