Уязвимость была обнаружена в файле Light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Этой проблеме подвержена функция AuthController::_initialize файла App/Admin/Controller/ChapterController.class.php компонента Chapter Controller. Манипуляция приводит к обходу авторизации.
Атака может быть инициирована удаленно. Эксплойт общедоступен и может быть использован. В этом продукте используется непрерывная доставка с чередующимися выпусками.
Поэтому сведения о версиях затронутых и обновленных выпусков недоступны. Проект был проинформирован о проблеме заранее через отчет о проблеме, но пока не ответил.
Показать оригинальное описание (EN)
A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component Chapter Controller. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit is publicly available and might be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Характеристики атаки
Последствия
Строка CVSS v4.0