Skip to content

Instantly share code, notes, and snippets.

@Mr-F0reigner
Last active December 5, 2023 07:28
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Mr-F0reigner/b05487f5ca52d17e214fffd6e1e0312a to your computer and use it in GitHub Desktop.
Save Mr-F0reigner/b05487f5ca52d17e214fffd6e1e0312a to your computer and use it in GitHub Desktop.
CVE-2023-47458
CVE-2023-40788
[description]
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to
escalate privileges via the lack of permissions control framework.
[Vulnerability Type]
Incorrect Access Control
[Vendor of Product]
https://gitee.com/smallc/SpringBlade
[Affected Product Code Base]
SpringBlade - SpringBlade <= 3.7.0
[Affected Component]
Upon auditing the code in the open-source repository, it was found that SpringBlade did not implement a permissions control framework and had insufficient user permission control, leading to privilege escalation vulnerabilities across all functional.
[Attack Type]
Remote
[Impact Escalation of Privileges]
true
[Attack Vectors]
Exploiting privilege escalation features directly through route construction.
[Reference]
http://springblade.com
https://gitee.com/smallc/SpringBlade
[discoverer]
Mr-F0reigner
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment