PT-2026-96308 · Unknown · Lamp-Cloud
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
lamp-cloud versions prior to 5.10.1
Description
The software fails to validate user identity in the 'PUT /anyone/baseInfo' and 'PUT /anyone/avatar' endpoints. This allows authenticated attackers to modify arbitrary user profiles by supplying target user IDs in the request bodies. Affected profile fields include nickname, ID card, sex, nation, education, work description, and avatar attachments.
Recommendations
Update lamp-cloud to a version newer than 5.10.0.
Restrict access to the 'PUT /anyone/baseInfo' and 'PUT /anyone/avatar' endpoints to minimize the risk of exploitation.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lamp-Cloud