ezBookkeeping 1.2.0 至 2.0.1 版本(不含 2.0.1)存在一个权限提升漏洞。攻击者持有 API 令牌即可通过 /api/v1/tokens/refresh.json 接口获取完整的会话令牌。由于 TokenRefreshHandler 从不检查令牌类型,攻击者可以将短期的或受 IP 限制的 API 令牌交换为有效期为 30 天的常规会话令牌,从而绕过 API 令牌的过期机制和允许列表(白名单)限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mayswind | ezBookkeeping | 1.2.0 ~ 2.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet