漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NamelessMC: Forum reactions bypass the "view own topics only" restriction
Vulnerability Description
NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce topic-level `view_other_topics` authorization. As a result, in forums where users may enter the forum but may only view their own topics, reactions can still be read and modified on other users' topics. Version 2.2.5 fixes the issue.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
授权机制缺失
Vulnerability Title
NamelessMC 安全漏洞
Vulnerability Description
NamelessMC是NamelessMC团队的一款免费、易于使用且功能强大的网站软件。适用于您的 Minecraft 服务器,其中包含大量功能。 NamelessMC 2.2.4版本存在安全漏洞,该漏洞源于未重新强制topic-level view_other_topics授权,可能导致在论坛中读取和修改其他用户主题的反应。
CVSS Information
N/A
Vulnerability Type
N/A