An issue in the delete function in the OaNotifyController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete notifications created by Administrators.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42746 | An issue in the delete function in the OaNotifyController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete notifications created by Administrators. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/thinkgem/jeesite/issues/517 |
|
History
Wed, 23 Oct 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-23T12:56:29.647Z
Reserved: 2023-07-25T00:00:00.000Z
Link: CVE-2023-38988
Updated: 2024-08-02T17:54:39.658Z
Status : Modified
Published: 2023-07-28T21:15:14.213
Modified: 2024-11-21T08:14:33.977
Link: CVE-2023-38988
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD