VYPR
Unrated severityOSV Advisory· Published Nov 8, 2018· Updated Aug 5, 2024

CVE-2018-19110

CVE-2018-19110

Description

Authenticated low-privileged users can access the skin-management functionality in tianti 2.3 due to missing authorization checks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated low-privileged users can access the skin-management functionality in tianti 2.3 due to missing authorization checks.

Vulnerability

In tianti 2.3, the skin-management feature lacks proper authorization checks. The usercontroller.java file maps the /skin/list request to the skinList function without verifying the user's permissions [1]. This allows any authenticated user to access the skin management interface regardless of their assigned role.

Exploitation

An attacker with a low-privileged authenticated account can directly request the URL http://127.0.0.1:8080/tianti-module-admin/user/skin/list to bypass intended permission restrictions [1]. No additional privileges or special conditions are required; simply having a valid session is sufficient.

Impact

Successful exploitation permits a low-privileged user to access and potentially modify skin settings, which should be restricted to administrators. This leads to unauthorized configuration changes and information disclosure of skin-related data [1].

Mitigation

As of the CVE publication date (2018-11-08), no official patch has been released. Administrators should implement manual authorization checks before executing the skinList function in usercontroller.java [1]. The vendor has been notified via the GitHub issue.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.