CVE-2023-27088
Last modified
CVE-2023-27088 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operations within the permission of the admin super administrator and can use this vulnerability to change the blacklist IP address in the system at will.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operations within the permission of the admin super administrator and can use this vulnerability to change the blacklist IP address in the system at will.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Feiqu-Opensource Project | Feiqu-Opensource | All versions |
References
- https://github.com/chen87548081/feiqu-opensource/issues/2Exploit, Issue Tracking, Third Party Advisory
- https://github.com/chen87548081/feiqu-opensource/issues/2Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-27088?
How severe is CVE-2023-27088?
How do I fix CVE-2023-27088?
Are you affected by CVE-2023-27088?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
