Filament 是一套用于加速 Laravel 开发的完整全栈组件集合。在 4.0.0 至 4.13.3 以及 5.8.3 版本中,基于应用的多因素认证(MFA)管理操作并未始终要求确认当前密码。拥有已认证用户会话访问权限的攻击者可以在不知道账户密码的情况下,通过提供现有的应用验证码或恢复码来设置基于应用的 MFA 并获取恢复码,或者禁用基于应用的 MFA 并重新生成恢复码。基于电子邮件的 MFA 不受此问题影响,且该漏洞本身并不允许未认证用户直接登录,但更改基于应用的 MFA 配置可能会导致合法用户被锁定而无法
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| filamentphp | filament | >= 4.0.0, < 4.13.2 |
affected |
>= 5.0.0, < 5.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filamentphp | filament | >= 4.0.0, < 4.13.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet