Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Xibo CMS has Preview and SavedReport IDOR via disableUserCheck without controller-level authorization
Vulnerability Description
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated user can manually construct a URL to preview campaigns/regions, and export saved reports belonging to other users. Exploitation of the vulnerability is possible on behalf of an authorized user who has any of the following privileges: Page which shows all Layouts that have been created for the purposes of Layout Management; page which shows all Campaigns that have been created for the purposes of Campaign Management; and page which shows all Reports that have been Saved. Users should upgrade to version 4.4.1 which fixes this issue. Upgrading to a fixed version is necessary to remediate.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Xibo 安全漏洞
Vulnerability Description
Xibo是Dan Garner个人开发者的一款数字标牌内容管理工具。 Xibo 4.4.1之前版本存在安全漏洞,该漏洞源于任何经过身份验证的用户可以手动构造URL来预览活动/区域并导出属于其他用户的已保存报告。
CVSS Information
N/A
Vulnerability Type
N/A