Description
The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/user/skin/list directly because controller\usercontroller.java maps a /skin/list request to the function skinList, and lacks an authorization check.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-10823 | The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/user/skin/list directly because controller\usercontroller.java maps a /skin/list request to the function skinList, and lacks an authorization check. |
References
| Link | Providers |
|---|---|
| https://github.com/xujeff/tianti/issues/29 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:30:04.360Z
Reserved: 2018-11-08T00:00:00.000Z
Link: CVE-2018-19110
No data.
Status : Modified
Published: 2018-11-08T08:29:00.527
Modified: 2024-11-21T03:57:20.983
Link: CVE-2018-19110
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD