Gophish 0.12.1 及更早版本中存在存储型和反射型跨站脚本(XSS)漏洞,攻击者可通过返回恶意的 SMTP 服务器错误消息注入脚本。当管理员查看活动结果或发送测试邮件时,攻击者若控制或拦截了发送配置中使用的 SMTP 服务器,即可执行恶意脚本,从而窃取 API 密钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107270 | 7.1 HIGH | Gophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create Endpoints |
| CVE-2026-107271 | 5.3 MEDIUM | Gophish through 0.12.1 Login Rate Limit Bypass via X-Forwarded-For Spoofing |
| CVE-2026-107273 | 4.3 MEDIUM | Gophish 0.11.0 through 0.12.1 SSRF via POST /api/import/site |
| CVE-2026-107269 | 3.7 LOW | Gophish through 0.12.1 Username Enumeration via POST /login Timing Discrepancy |
No comments yet