Fuyang Lipengjun Platform Improper Authorization Vulnerability in TopicController

Vulnerability

An improper authorization vulnerability has been identified in Fuyang Lipengjun Platform version 1.0. The issue resides in the TopicController function within the file '/topic/queryAll'. This vulnerability allows authenticated users, regardless of their privilege level, to access data that should be restricted to administrators. The flaw can be exploited remotely, and a public proof-of-concept exploit is available.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive information, allowing users to view data that should be restricted based on their role.

Reproduction

To reproduce this vulnerability, log into the application with any user account, including those with low privileges. Then, send a GET request to the '/topic/queryAll' endpoint. The server will respond with a complete list of topic information, which is typically only accessible to users with administrative privileges.

Added: Sep 23, 2025, 12:44 AM
Updated: Sep 23, 2025, 12:44 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.