CVE-2018-19109

xujeff/tianti
on github

Published

Severity

CVSS v3:
8.8 HIGH
CVSS v2:
6.5 MEDIUM

Description

tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to read the column list page or edit a column.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:tianti_project:tianti:2.3:*:*:*:*:*:*:*n/an/a2.3

External Links