Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile
Vulnerability Description
Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile issue a session based on the invitation email match without password verification, allowing a registered user to take over any non-blocked profile. This issue is fixed in version 2.14.5.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
认证机制不恰当
Vulnerability Title
penpot 授权问题漏洞
Vulnerability Description
penpot penpot是penpot公司开源的一款开源的设计和原型制作平台。 penpot 2.14.5之前版本存在授权问题漏洞,该漏洞源于暴露邀请令牌和未进行密码验证,可能导致注册用户接管任何非封锁配置文件。
CVSS Information
N/A
Vulnerability Type
N/A