Flame 2.4.0 及更早版本在 POST /api/auth 登录接口中存在一种“对过多认证尝试限制不当”的安全漏洞。该漏洞允许未认证的攻击者对管理员密码执行暴力破解。攻击者可以无限制地提交密码猜测请求,系统未实施速率限制、尝试次数计数、账户锁定或延迟等防护机制,从而导致攻击者能够获取完整的管理员权限,并修改应用程序配置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pawelmalak | flame | 0 ~ 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100418 | 5.3 MEDIUM | Flame through 2.4.0 Information Exposure via GET /api/config |
| CVE-2026-100502 | 5.0 MEDIUM | Flame through 2.4.0 Admin Token Insufficient Session Expiration |
No comments yet