MyBooks(也被称为 Talebook)是一个电子书管理 Web 服务器。在版本 3.41.2 及更早版本中, 文件中的 处理器在处理 请求时,未强制执行 配置标志。尽管前端在 标志为 时会隐藏注册控件,但该后端端点仍允许调用。未认证的远程攻击者可以直接调用该端点,在管理员已禁用公开注册的功能的实例上创建有效账户。 此外, 中的 函数也未验证账户的“激活状态”标志,因此新创建且尚未激活的账户可以立即进行身份验证,并访问用户级别的 API 功能。 此漏洞绕过了预期的账户创建策略,攻击者可借此获取低权限账户,从而触
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PoxenStudio | talebook | < 3.42.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PoxenStudio | talebook | < 3.42.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45272 | 9.4 CRITICAL | MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File |
| CVE-2026-45273 | 8.7 HIGH | MyBooks: Privilege Escalation via Missing Authorization on Admin Settings Endpoint |
No comments yet