Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
insa-auth Open-Redirect on provided CAS server login endpoint
Vulnerability Description
insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's secondary authentication bridge, potentially revealing basic student information (name and number). However, the issue posed minimal risk, was never exploited, and had limited impact. A fix was implemented promptly on May 3, 2025.
CVSS Information
N/A
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Vulnerability Title
insa-auth 输入验证错误漏洞
Vulnerability Description
insa-auth是genda开源的一个认证服务工具。 insa-auth存在输入验证错误漏洞,该漏洞源于第三方网站可访问服务器辅助身份验证桥接,可能泄露基本信息。
CVSS Information
N/A
Vulnerability Type
N/A