漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key
Vulnerability Description
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Kiteworks 安全漏洞
Vulnerability Description
Kiteworks是美国Kiteworks公司的一个安全私有网络数据软件。 Kiteworks 9.3.0之前版本存在安全漏洞,该漏洞源于不安全的直接对象引用,可能导致认证攻击者篡改其他用户的内部审批流程配置。
CVSS Information
N/A
Vulnerability Type
N/A