漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Chengdu Everbrite Network Technology BeikeShop Stripe Plugin StripeController.php callback improper authorization
Vulnerability Description
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authorization. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named 6719e0fc690ea0a998452092862e0f0a17c65968. It is suggested to install a patch to address this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
授权机制不恰当
Vulnerability Title
BeikeShop 授权问题漏洞
Vulnerability Description
BeikeShop是BeikeShop开源的一个开源PHP电商平台,支持多语言多币种与快速部署。 BeikeShop 1.6.0.22及之前版本存在授权问题漏洞,该漏洞源于Stripe Plugin组件中文件plugins/Stripe/Controllers/StripeController.php的函数callback对参数Request的操作,可能导致授权不当。
CVSS Information
N/A
Vulnerability Type
N/A