Nginx Proxy Manager 2.16.0 及以下版本在认证端点缺乏速率限制机制,导致未授权的攻击者可以向任意账户发起无限次的密码猜测攻击。攻击者可以通过 POST /api/tokens 暴力破解登录凭证,随后再通过 POST /api/tokens/2fa 猜测一次性密码(TOTP)验证码,从而获取完整的会话访问权限并实现对系统的完全控制及管理员权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NginxProxyManager | nginx-proxy-manager | 0 ~ 2.16.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet