priority-software priority 通过用户控制密钥绕过授权机制

admin 2023-11-30 07:04:25 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
priority-software priority 通过用户控制密钥绕过授权机制

CVE编号

CVE-2022-23173

利用情况

暂无

补丁情况

N/A

披露时间

2022-07-06
漏洞描述
this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - demo site" then he can see in this menu all the functionality of the application. If the attacker will try to click on one of the links, he will get an answer that he is not authorized because he needs to log in with credentials. after he performed log in to the system there are some functionalities that the specific user is not allowed to perform because he was configured with low privileges however all the attacker need to do in order to achieve his goals is to change the value of the prog step parameter from 0 to 1 or more and then the attacker could access to some of the functionality the web application that he couldn't perform it before the parameter changed.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://www.gov.il/en/Departments/faq/cve_advisories
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 priority-software priority * Up to (excluding) 22.0
CVSS3评分 6.3
  • 攻击路径 网络
  • 攻击复杂度 低
  • 权限要求 低
  • 影响范围 未更改
  • 用户交互 无
  • 可用性 低
  • 保密性 低
  • 完整性 低
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE-ID 漏洞类型
CWE-639 通过用户控制密钥绕过授权机制
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0