Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged with his username to bypass authentication.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
yf-exam 安全漏洞
Vulnerability Description
yf-exam(云帆培训考试系统)是CleverStupidDog个人开发者的一个培训考试系统。 CleverStupidDog yf-exam 1.8.0版本存在安全漏洞,该漏洞源于存在认证绕过的漏洞,任何在24小时内登录的用户,可以用他的用户名伪造令牌以绕过身份验证。
CVSS Information
N/A
Vulnerability Type
N/A