Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-41191
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
API giving out files without key
Source: NVD (National Vulnerability Database)
Vulnerability Description
Roblox-Purchasing-Hub is an open source Roblox product purchasing hub. A security risk in versions 1.0.1 and prior allowed people who have someone's API URL to get product files without an API key. This issue is fixed in version 1.0.2. As a workaround, add `@require_apikey` in `BOT/lib/cogs/website.py` under the route for `/v1/products`.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
对输出编码和转义不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Roblox-Purchasing-Hub 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Roblox-Purchasing-Hub是一个 Roblox 产品采购中心。 Roblox-Purchasing-Hub 存在安全漏洞,该漏洞源于 Roblox-Purchasing-Hub 1.0.1 版本及之前版本中的安全风险允许拥有某人的 API URL 的人在没有 API 密钥的情况下获取产品文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Redon-TechRoblox-Purchasing-Hub < 1.0.2 -
II. Public POCs for CVE-2021-41191
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-41191
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2021-41191

No comments yet


Leave a comment