Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SourceCodester Customer Review App review_app.py get_all_reviews denial of service
Vulnerability Description
A vulnerability was found in SourceCodester Customer Review App 1.0. Affected by this vulnerability is the function add_review/save_review/get_all_reviews of the file review_app.py. Performing a manipulation of the argument name/comment results in denial of service. The attack requires a local approach. The exploit has been made public and could be used.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
不恰当的资源关闭或释放
Vulnerability Title
SourceCodester Customer Review App 安全漏洞
Vulnerability Description
SourceCodester Customer Review App是SourceCodester开源的一个客户评论应用程序。 SourceCodester Customer Review App 1.0版本存在安全漏洞,该漏洞源于文件review_app.py中函数add_review/save_review/get_all_reviews对参数name/comment的错误操作,可能导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A