漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Frogman: API tokens stored in plaintext
Vulnerability Description
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by Tools/CreateApiToken.php:33-36 as raw bin2hex(random_bytes(32)) strings in oc_api_tokens, and Frogman.class.php:78 authenticated the X-Frogman-Token header by comparing it with the stored raw value, allowing database read access to recover reusable active tokens at their assigned permission level, including admin. This issue is fixed in version 1.6.2.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
明文存储口令
Vulnerability Title
Michael White Frogman 信任管理问题漏洞
Vulnerability Description
Michael White Frogman是Michael White个人开发者的一款通过 MCP 和 HTTP API 实现无头 PBX 控制的软件。 Michael White Frogman 1.6.2之前版本存在信任管理问题漏洞,该漏洞源于Frogman将API令牌以原始字符串形式存储,并通过比较存储原始值来验证X-Frogman-Token标头,可能允许数据库读取访问恢复可重用的活动令牌,达到其分配的权限级别,包括管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A