Guns through 8.3.5 Improper Access Control via SysNoticeController
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated users without assigned roles can exploit this to create, edit, delete, publish and retract system-wide notices affecting arbitrary users and departments.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
stylefeng · GunsReferences
https://github.com/stylefeng/Gunshttps://github.com/stylefeng/Guns/blob/2a12947733945d5c06197d99ecaa77d7f2b0aeba/src/main/java/cn/stylefeng/guns/core/security/TokenAndPermissionInterceptor.java#L110-L119https://github.com/stylefeng/Guns/issues/119https://repo1.maven.org/maven2/com/javaguns/roses/system-business-portal/8.3.5/system-business-portal-8.3.5-sources.jarhttps://www.vulncheck.com/advisories/guns-through-8.3.5-improper-access-control-via-sysnoticecontroller