Description
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-16195 | newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed. |
References
| Link | Providers |
|---|---|
| https://github.com/newbee-ltd/newbee-mall/issues/34 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T14:58:15.000Z
Reserved: 2020-08-13T00:00:00.000Z
Link: CVE-2020-23448
No data.
Status : Modified
Published: 2021-01-26T18:15:42.740
Modified: 2024-11-21T05:13:48.720
Link: CVE-2020-23448
No data.
OpenCVE Enrichment
No data.
EUVD