漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PolarLearn: Any password authenticates banned accounts and grants API access
Vulnerability Description
PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned accounts before verifying the supplied password. That session is then accepted across authenticated /api routes, enabling account data access and authenticated actions as the banned user.
CVSS Information
N/A
Vulnerability Type
认证机制不恰当
Vulnerability Title
PolarLearn 授权问题漏洞
Vulnerability Description
PolarLearn是PolarNL开源的一个在线学习平台。 PolarLearn 0-PRERELEASE-15及之前版本存在授权问题漏洞,该漏洞源于为已禁用账户创建有效会话,可能导致未经授权的访问。
CVSS Information
N/A
Vulnerability Type
N/A