OpenSave 在 2.4.0-beta.1 之前的版本未能对 WAN(广域网)中继请求中的发送者身份进行有效验证,导致未配对的房间成员可以通过伪造 RelayMessage 的 From 字段来冒充已配对设备。攻击者若知晓房间代码,即可加入该房间,从公告中读取已配对的对端标识符,并发送伪造请求以访问受保护的同步路由,包括保存数据、快照及文件操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet