在 X-SpringBoot 6.0 及之前版本中, 端点存在安全漏洞,该端点会返回 和 凭证,而未进行任何身份认证或字段过滤。攻击者无需认证即可获取这些凭证,进而利用任意租户的短信服务提供商发送任意短信,从而实现短信轰炸(SMS bombing)和身份冒充攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yzcheng90 | X-SpringBoot | 0 ~ 6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97063 | 9.1 CRITICAL | X-SpringBoot through 6.0 Authentication Bypass via Login Code |
| CVE-2026-97064 | 9.1 CRITICAL | X-SpringBoot through 6.0 Authentication Bypass via Static Master Code |
| CVE-2026-97060 | 7.2 HIGH | X-SpringBoot through 6.0 Authorization Bypass via User Management |
No comments yet