CyberRota Analysis
AI-GeneratedA high-severity vulnerability exists in the Java component of realjerrytang tacomall 1.0.0, specifically within the OrgStaffServiceImpl.add function of ApiMaApplication.java, where improper authorization can be triggered through manipulation of the isAdmin/jobId argument. This flaw allows for potential remote exploitation, as publicly available exploits may be utilized by attackers. Organizations using this software should prioritize immediate remediation to mitigate the risk of unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.