CVE-2023-44794

An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.
References
Link Resource
https://github.com/dromara/Sa-Token/issues/515 Exploit Issue Tracking Vendor Advisory
https://github.com/dromara/Sa-Token/issues/515 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:dromara:sa-token:*:*:*:*:*:*:*:*
OR cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:26

Type Values Removed Values Added
References () https://github.com/dromara/Sa-Token/issues/515 - Exploit, Issue Tracking, Vendor Advisory () https://github.com/dromara/Sa-Token/issues/515 - Exploit, Issue Tracking, Vendor Advisory

12 Sep 2024, 15:35

Type Values Removed Values Added
CWE CWE-284

31 Oct 2023, 20:08

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References (MISC) https://github.com/dromara/Sa-Token/issues/515 - (MISC) https://github.com/dromara/Sa-Token/issues/515 - Exploit, Issue Tracking, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Vmware
Dromara sa-token
Vmware spring Boot
Dromara
Vmware spring Framework
CPE cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:dromara:sa-token:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*

25 Oct 2023, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-25 18:17

Updated : 2024-11-21 08:26


NVD link : CVE-2023-44794

Mitre link : CVE-2023-44794

CVE.ORG link : CVE-2023-44794


JSON object : View

Products Affected

vmware

  • spring_framework
  • spring_boot

dromara

  • sa-token
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control