IceCMS icon indicating copy to clipboard operation
IceCMS copied to clipboard

[vulnerability security] Vertical Privilege Escalation Vulnerability

Open GatekeeperBuster opened this issue 6 months ago • 0 comments

Recently, our team discovered a security vulnerability that has led to an unauthorized access issue in the latest version of the project, which could pose a serious risk of information leakage.

The URL of the vulnerability is http://localhost:port/User/GetUserInfoByid/{userid} within the method. This means that attackers can use the backend API directly without authentication.

Please note that the URL provided is a placeholder and should be replaced with the actual URL of the vulnerability if you are sharing this information with others. Also, it's important to address such vulnerabilities promptly to mitigate any potential risks. image

GatekeeperBuster avatar Aug 05 '24 13:08 GatekeeperBuster