Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association
Vulnerability Description
Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is linked to the active session. The platform incorrectly associates the deletion state with the device identifier, causing the affected device or browser environment to be redirected to an account-disabled page for approximately 30 days, preventing any account login or registration from that device.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
过度限制的账户封锁机制
Vulnerability Title
Capgo 授权问题漏洞
Vulnerability Description
Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.28.2之前版本存在授权问题漏洞,该漏洞源于账户删除流程中的拒绝服务问题,导致平台错误地将删除状态与设备标识符关联,攻击者可通过触发账户删除来阻止身份验证和注册功能,致使受影响设备或浏览器环境被重定向到账户禁用页面约30天。
CVSS Information
N/A
Vulnerability Type
N/A