漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Missing authorization checks in Wertheim SafeController Software allow low-privileged users to access restricted functions
Vulnerability Description
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. An authenticated attacker with minimal privileges can access endpoints that are not visible in the frontend but remain directly reachable. This allows the attacker to perform restricted actions such as switching the user's branch, uploading arbitrary files, downloading arbitrary files, and viewing details of arbitrary branches.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
Wertheim SafeController Software for VAULT ROOMS 授权问题漏洞
Vulnerability Description
Wertheim SafeController Software for VAULT ROOMS是Wertheim公司的一款金库安全保险柜系统的控制软件。 Wertheim SafeController Software for VAULT ROOMS 6.15.8328.28014版本存在授权问题漏洞,该漏洞源于缺少授权检查,可能导致经过身份验证的攻击者访问隐藏端点,执行切换分支、上传任意文件、下载任意文件以及查看任意分支详细信息等受限操作。
CVSS Information
N/A
Vulnerability Type
N/A