Brokerage Wave是Brokerage公司的一个前台产品。 Brokerage Wave 2.0版本存在安全漏洞,该漏洞源于API端点对无效输入的异常处理不当,从而攻击者可通过在API请求中为userId参数提供无效输入来生成包含目标系统敏感信息的错误消息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Brokerage Technology Solutions | Wave 2.0 | <1.1.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-51561 | Authentication bypass Vulnerability in Aero | |
| CVE-2024-51558 | Brute Force Attack Vulnerability in Wave 2.0 | |
| CVE-2024-51556 | Sensitive Information Disclosure Vulnerability in Wave 2.0 | |
| CVE-2024-51557 | No Rate Limiting Vulnerability in Wave 2.0 | |
| CVE-2024-51559 | Improper Access Control Vulnerability in Wave 2.0 |
No comments yet