Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Termix: Account Takeover via Global Settings Disclosure
Vulnerability Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /database/export endpoint creates a user export that includes the global settings table even though the rest of the export is user-scoped. The settings table contains reset_code_ and temp_reset_token_ password-reset artifacts, allowing a low-privileged authenticated user to recover another local account's reset code and complete the normal password-reset flow. Successful exploitation results in local-user account takeover and administrative compromise when the victim is an administrator. This issue is fixed in version 2.3.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
授权机制缺失
Vulnerability Title
Termix 授权问题漏洞
Vulnerability Description
termix是termix个人开发者的一个终端模拟器。 Termix 2.3.2之前版本存在授权问题漏洞,该漏洞源于/database/export端点导出数据时包含全局设置表,导致密码重置信息泄露,低权限认证用户可利用重置代码接管本地账户,若受害者是管理员则可实现管理权限接管。
CVSS Information
N/A
Vulnerability Type
N/A