Integrics Enswitch 3.13 至 4.4 版本在 接口中存在认证绕过漏洞,允许未经身份验证的攻击者通过省略 reset 参数来更改账户密码。攻击者可针对那些没有待处理重置请求、且其空的 reset_key 与默认空值相匹配的账户,在枚举出有效用户名后接管管理员账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet