CVE-2023-27088
Summary
| CVE | CVE-2023-27088 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-08 16:15:00 UTC |
| Updated | 2023-03-14 15:29:00 UTC |
| Description | feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operations within the permission of the admin super administrator and can use this vulnerability to change the blacklist IP address in the system at will. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Feiqu-opensource Project | Feiqu-opensource | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| feiqu-opensource overreach vulnerability · Issue #2 · chen87548081/feiqu-opensource · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.