Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ModernBill 5.0.4 and earlier uses cURL with insecure settings for CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST that do not verify SSL certificates, which allows remote attackers to read network traffic via a man-in-the-middle (MITM) attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ModernBill SSL CURLOPT_SSL_VERIFYPEER和CURLOPT_SSL_VERIFYHOST设置中间攻击漏洞
Vulnerability Description
ModernBill 5.0.4及早期版本使用cURL时,对不检验SSL证书的CURLOPT_SSL_VERIFYPEER和CURLOPT_SSL_VERIFYHOST设置不安全,利用此漏洞,远程攻击者可借助中间人(MITM)攻击读取网络通信。
CVSS Information
N/A
Vulnerability Type
N/A