CasaOS是一个简单、易用、优雅的开源家庭云系统。 CasaOS-UserService 0.4.6之前版本存在安全漏洞,该漏洞源于对URL路径过滤不严,导致攻击者可以在系统上获取任何文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IceWhaleTech | CasaOS-UserService | < 0.4.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-24767 | 9.1 CRITICAL | CasaOS Improper Restriction of Excessive Authentication Attempts vulnerability |
| CVE-2024-24766 | 6.2 MEDIUM | CasaOS Username Enumeration |
No comments yet