HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or t
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| sysadminsmedia | homebox | < 0.26.0 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| sysadminsmedia | homebox | < 0.26.0 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-48976 | 8.1 HIGH | HomeBox: Cross-Tenant IDOR in Notifier Update Leaks Shoutrrr Credentials and Allows Webhoo |
| CVE-2026-48826 | 8.1 HIGH | HomeBox: Cross-Group Inventory Wipe in Homebox via Global Owner Role and X-Tenant Header S |
| CVE-2026-48975 | 8.1 HIGH | HomeBox: Cross-Tenant IDOR in MaintenanceEntry Update and Delete Allows Tampering and Dest |
| CVE-2026-55473 | 6.0 MEDIUM | HomeBox: Notifier SSRF guard misses NAT64 prefixes (64:ff9b::/96, 64:ff9b:1::/48) — generi |
暂无评论