PT-2018-14809 · Tianti · Tianti

Zsdlove

·

Publicado

2018-11-08

·

Atualizado

2020-08-24

·

CVE-2018-19110

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions tianti version 2.3
Description The issue allows remote authenticated users to bypass intended permission restrictions. This is possible by visiting the "tianti-module-admin/user/skin/list" endpoint directly. The UserController.java maps a /skin/list request to the skinList function, which lacks an authorization check.
Recommendations For tianti version 2.3, consider adding an authorization check to the skinList function in UserController.java to prevent unauthorized access. As a temporary workaround, restrict access to the "tianti-module-admin/user/skin/list" endpoint to minimize the risk of exploitation.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-19110

Produtos afetados

Tianti