An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Administrator's role information.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42747 | An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Administrator's role information. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/thinkgem/jeesite/issues/518 |
|
History
Tue, 22 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-22T15:37:10.557Z
Reserved: 2023-07-25T00:00:00.000Z
Link: CVE-2023-38989
Updated: 2024-08-02T17:54:39.723Z
Status : Modified
Published: 2023-07-31T18:15:10.320
Modified: 2024-11-21T08:14:34.133
Link: CVE-2023-38989
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD