social-media-skeleton是fobybus个人开发者的一个使用 php、css、javascript 和 html 实现的未完成的社交媒体项目。 social-media-skeleton 1.0.5之前版本存在代码问题漏洞,该漏洞源于没有正确限制用户会话的生命周期,导致存在会话过期不足问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| fobybus | social-media-skeleton | < 1.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-40173 | 7.5 HIGH | Unsalted passwords in fobybus/social-media-skeleton |
| CVE-2023-40172 | 6.5 MEDIUM | Cross-Site Request Forgery (CSRF) in fobybus/social-media-skeleton |
No comments yet