漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SolidInvoice: API tokens stored as plaintext in the database allowing full credential compromise on database breach
Vulnerability Description
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconfigured replica, or insider access — immediately obtains all API credentials for every user with no further effort. This issue has been patched in version 2.3.17.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
敏感数据的明文存储
Vulnerability Title
SolidInvoice 安全漏洞
Vulnerability Description
SolidInvoice是SolidInvoice开源的一个发票解决方案应用程序。 SolidInvoice 2.3.17之前版本存在安全漏洞,该漏洞源于API令牌以明文形式存储在api_tokens数据库表中,可能导致任何获得数据库读取权限的攻击者获取所有用户的API凭据。
CVSS Information
N/A
Vulnerability Type
N/A