漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Hardcoded Cryptographic Keys and Weak IV Generation in linqi
Vulnerability Description
The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for AES/CBC encryption, making known-plaintext attacks feasible. An attacker with local access can leverage these vulnerabilities to decrypt sensitive obfuscated strings, including ConnectionString values containing database credentials from appsettings.json.
CVSS Information
N/A
Vulnerability Type
使用硬编码的密码学密钥
Vulnerability Title
Linqi 安全漏洞
Vulnerability Description
Linqi是德国Linqi公司的一款结合真人语言交流与AI反馈的英语口语练习平台。 linqi存在安全漏洞,该漏洞源于硬编码加密密钥及弱算法生成初始化向量,导致本地攻击者可解密敏感混淆字符串。
CVSS Information
N/A
Vulnerability Type
N/A