CVE Details
Basic Information
| Title |
jack0240 魏 bskms 蓝天幼儿园管理系统 User Creation addUser improper authorization |
| Type |
cve |
| Published |
2025-06-03T19:00:22.162Z |
| Last Seen |
|
Product Information
| Vendor |
jack0240 魏 |
| Product |
bskms 蓝天幼儿园管理系统 |
| Version |
dffe6640b5b54d8e29da6f060e0493fea74b3fad |
CVSS Information
| Base Score |
6.9 (MEDIUM) |
| Attack Vector |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
| Confidentiality Impact |
|
| Integrity Impact |
|
| Availability Impact |
|
AI Analysis
| AI Description |
A vulnerability in the bskms 蓝天幼儿园管理系统 allows remote attackers to create users without proper authorization, potentially leading to unauthorized access. The CVSS score is 6.9, indicating a medium severity level. |
| AI Severity |
Medium |
| Vendor |
jack0240 魏 |
| Product |
bskms 蓝天幼儿园管理系统 |
| Affected Version |
dffe6640b5b54d8e29da6f060e0493fea74b3fad |
Additional Information
| CVE List |
|
| CWE List |
CWE-285, CWE-266 |
| Bulletin Family |
|
| Source Data |
jack0240 魏 bskms 蓝天幼儿园管理系统 dffe6640b5b54d8e29da6f060e0493fea74b3fad |
Source Information
| Source Data |
jack0240 魏 bskms 蓝天幼儿园管理系统 dffe6640b5b54d8e29da6f060e0493fea74b3fad |
| Source Link |
|
Description
A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sa/addUser of the component User Creation Handler. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
CVSS Score Summary
View Full CVE Details