Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GoPhish 安全漏洞
Vulnerability Description
GoPhish是GoPhish开源的一款开源的网络钓鱼框架。 Gophish 0.12.1及之前版本存在安全漏洞,该漏洞源于访问控制不当,管理面板在每次登录时于页面渲染的HTML或JavaScript中直接暴露用户的长效API密钥,可能导致浏览器环境中运行的任意脚本获取永久API凭据。
CVSS Information
N/A
Vulnerability Type
N/A