在 TaleLin lin-cms-spring-boot(最高至 0.2.1 版本)中发现了一个漏洞。该漏洞影响组件 book 的 BookController.java 文件中的 getBook 函数,文件路径为 src/main/java/io/github/talelin/latticy/controller/v1/BookController.java。对参数 ID 进行操作会导致授权不当。该漏洞可以被远程利用。目前该漏洞的利用代码已被公开,并可被攻击者使用。厂商在披露前已获知此问题,但对此未作任何回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TaleLin | lin-cms-spring-boot | 0.2.0 |
affected |
0.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TaleLin | lin-cms-spring-boot | 0.2.0 |
cpe:2.3:a:talelin:lin-cms-spring-boot:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96882 | 5.3 MEDIUM | TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authoriz |
| CVE-2026-96881 | 5.3 MEDIUM | TaleLin lin-cms-spring-boot book Endpoint BookController.java getBooks improper authorizat |
No comments yet