Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Sanluan PublicCMS Trade Payment Flow TradeOrderController.java AccountGatewayComponent.pay logic error
Vulnerability Description
A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.java of the component Trade Payment Flow. The manipulation leads to business logic errors. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
业务逻辑错误
Vulnerability Title
PublicCMS 安全漏洞
Vulnerability Description
PublicCMS是中国PublicCMS公司的一套使用Java语言编写的开源内容管理系统(CMS)。 Sanluan PublicCMS 5.202506.d版本存在安全漏洞,该漏洞源于Trade Payment Flow组件中publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.java文件的TradeOrderController.pay/TradePaymentController
CVSS Information
N/A
Vulnerability Type
N/A