漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
e107: Broken Access Control in e107 comment edit allows cross-user comment modification
Vulnerability Description
e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to edit comments posted by others. This stems from inadequate server-side access control validation, where the application depends only on a predictable identifier in the request to determine which comment to edit, without confirming the requesting user’s ownership of the comment. This vulnerability is fixed in 2.3.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
访问控制不恰当
Vulnerability Title
e107 安全漏洞
Vulnerability Description
e107是E107团队的一套开源、免费且基于PHP和MySQL的内容管理系统(CMS)。该系统支持多种插件和外观主题,可作为个人博客、讨论社区、档案资料库等。 e107 2.3.4之前版本存在安全漏洞,该漏洞源于访问控制失效,应用程序仅依赖请求中的可预测标识符确定要编辑的评论而未确认用户所有权,可能导致未经授权的经过身份验证的用户编辑他人发布的评论。
CVSS Information
N/A
Vulnerability Type
N/A