Pingvin Share 在版本 0.19.0 至 1.22.0(不包括 1.22.0)中存在一个不正确的身份验证漏洞。攻击者可以利用 OAuthService.signUp() 中的自动 OAuth 邮箱链接功能,对远程未认证的攻击者实现账户接管。具体而言,攻击者可以在启用了 OAuth/OIDC 提供方的情况下,注册受害者未验证的邮箱,并通过利用 GenericOidcProvider 中缺失的 email_verified 检查,以受害者身份登录,包括管理员账户,同时绕过双因素认证(TOTP)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| smp46 | pingvin-share-x | 0.19.0< 1.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| smp46 | pingvin-share-x | 0.19.0 ~ 1.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet