Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
1000 Projects Portfolio Management System MCA update_passwd_process.php authorization
Vulnerability Description
A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation of the argument temp_user results in authorization bypass. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
1000 Projects Portfolio Management System MCA 授权问题漏洞
Vulnerability Description
1000 Projects Portfolio Management System MCA是1000 Projects开源的一个组合管理系统。 1000 Projects Portfolio Management System MCA 1.0版本存在授权问题漏洞,该漏洞源于文件update_passwd_process.php中参数temp_user操作不当,可能导致授权绕过。
CVSS Information
N/A
Vulnerability Type
N/A