AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://alist.nn.ci/zh/ | product |
https://github.com/J6451/CVE-2023-31726 | third party advisory |
https://github.com/J6451/CVE-2023-31726/blob/main/CVE-2023-31726.py |