An issue in the delete function in the OaNotifyController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete notifications created by Administrators.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Jeesite |
Jeesite |
1.2.6 (including) |
1.2.6 (including) |
References