Описание
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resulting in an authorization bypass vulnerability.
Ссылки
- Third Party Advisory
- Patch
- ExploitIssue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:youlai:youlai-boot:2.21.1:*:*:*:*:*:*:*
EPSS
Процентиль: 9%
0.00031
Низкий
7.1 High
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 7.1
github
около 2 месяцев назад
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resulting in an authorization bypass vulnerability.
EPSS
Процентиль: 9%
0.00031
Низкий
7.1 High
CVSS3
Дефекты
CWE-284