Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In ebankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP messages to any e-mail address or phone number without validation. (It cannot be exploited with e-mail addresses or phone numbers that are registered in the application.)
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ebankIT 安全漏洞
Vulnerability Description
ebankIT是葡萄牙ebankIT公司的一个银行软件。 ebankIT 6版本存在安全漏洞,该漏洞源于无需验证就可以生成OTP消息到任何电子邮件地址或电话号码。
CVSS Information
N/A
Vulnerability Type
N/A