A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://vuldb.com/?id.287865 | third party advisory vdb entry |
https://vuldb.com/?ctiid.287865 | signature vdb entry permissions required |
https://vuldb.com/?submit.458895 | third party advisory vdb entry |
https://github.com/cydtseng/Vulnerability-Research/blob/main/ujcms/IDOR-UsernameEnumeration.md | third party advisory exploit |