PT-2026-102453 · Realjerrytang · Tacomall
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
realjerrytang tacomall version 1.0.0
Description
An improper authorization issue exists in the api-admin Backend component within the file ApiMaApplication.java. The flaw occurs in the
OrgStaffServiceImpl.add() function, where manipulating the isAdmin or jobId arguments allows for remote exploitation.Recommendations
For version 1.0.0, restrict the use of the
OrgStaffServiceImpl.add() function or validate the isAdmin and jobId arguments to prevent unauthorized access.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Incorrect Privilege Assignment
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tacomall