HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2025-27893
发布日期2025-03-11T00:00:00.000Z
更新日期2025-03-11T13:37:25.862Z
状态PUBLISHED
受影响的供应商Archer
受影响的产品Archer
描述In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. This enables unauthorized modification of system-generated metadata, compromising data integrity and potentially impacting auditing, compliance, and security controls.

参考链接:

Image Additional Image