漏洞标题
ColumbiaSoft Document Locator WebTools 登录错误,身份验证不正确
漏洞描述信息
"ColumbiaSoft Document Locator WebTools 登录 improper authentication" 可以翻译为:“哥伦比亚软体文件定位器网络工具登录验证不正确”。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
认证机制不恰当
漏洞标题
ColumbiaSoft Document Locator WebTools login improper authentication
漏洞描述信息
A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper authentication. It is possible to initiate the attack remotely. Upgrading to version 7.2 SP4 and 2021.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-243729 was assigned to this vulnerability.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
漏洞类别
认证机制不恰当
漏洞标题
ColumbiaSoft Document Locator 安全漏洞
漏洞描述信息
ColumbiaSoft Document Locator是ColumbiaSoft公司的一个文档管理系统。 ColumbiaSoft Document Locator 7.2 SP4之前版本存在安全漏洞,该漏洞源于文件/api/authentication/login的参数Server会导致不正确的身份验证。
CVSS信息
N/A
漏洞类别
其他