Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.
2025-05-05T20:15:20.470
2025-10-14T20:47:34.917
Analyzed
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | zhaojun1998 | shiro-action | ≤ 0.6 | Yes |