Vulnerabilities > CVE-2023-38989 - Missing Authorization vulnerability in Jeesite 1.2.6
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Administrator's role information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |