Withstars Books Management System Background Interface Missing Authorization Vulnerability

Vulnerability

A critical unauthorized access vulnerability has been identified in Withstars Books Management System version 1.0. This issue arises from a lack of proper authorization checks in the background interface, specifically within the article management component. As a result, unauthorized users can access sensitive functions and information remotely, potentially leading to data breaches or unauthorized modifications.

Impact

Exploitation of this vulnerability allows unauthorized users to access the background interface and article management functions, which could result in unauthorized operations or access to sensitive information.

Reproduction

To reproduce this vulnerability, access the '/admin/article/list' endpoint without logging in. The absence of authorization checks will allow access to the article management interface. This can be done by sending a GET request to the endpoint, omitting any authentication cookies.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.