Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Zyosoft|School App - Insecure Direct Object Reference
Vulnerability Description
School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read and modify other users' data.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Zyosoft School App 安全漏洞
Vulnerability Description
Zyosoft School App是中国台湾日躍科技(Zyosoft)公司的一款面向学校管理与家校沟通的移动应用。 Zyosoft School App存在安全漏洞,该漏洞源于不安全的直接对象引用,可能导致经过身份验证的远程攻击者修改特定参数以读取和修改其他用户的数据。
CVSS Information
N/A
Vulnerability Type
N/A