WordPress 的 Mstore Api 插件存在身份验证绕过漏洞,原因是通过 JWT 伪造(影响版本至 4.20.0 及更早版本)。该漏洞源于 函数中缺失密码学签名验证:该函数虽然解码并验证了 Firebase ID Token 的声明字段(如 、 、 、 ),但从未调用 或等效方法,将 JWT 签名与 Google 实际的公钥证书进行校验。 这使得未认证的 attackers 能够使用自行生成的 RSA 密钥对签名一个 Firebase 电话认证 JWT,从而冒充任意电话号码,进而导致对现有 WordPre
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| inspireui | MStore API – Create Native Android & iOS Apps On The Cloud | ≤ 4.20.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| inspireui | MStore API – Create Native Android & iOS Apps On The Cloud | 0 ~ 4.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet