漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Missing Authorization in DinoRANK
Vulnerability Description
A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
DinoRANK 安全漏洞
Vulnerability Description
DinoRANK是DinoRANK公司的一个 SEO 平台。 DinoRANK存在安全漏洞,该漏洞源于缺少授权,可能导致攻击者访问任何用户的发票。
CVSS Information
N/A
Vulnerability Type
N/A