Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在SQL注入漏洞,该漏洞源于对POST /private/admin_stats端点中的limit参数处理不当,未经验证的请求体参数被直接插值到Cloudflare Analytics Engine SQL查询中,可能导致具有平台管理员凭据的攻击者注入SQL片段来枚举数据集模式、提取分析数据或对分析后端造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56241 | 8.3 HIGH | Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right |
| CVE-2026-56313 | 8.1 HIGH | Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint |
| CVE-2026-56238 | 7.5 HIGH | Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint |
| CVE-2026-56308 | 7.3 HIGH | Capgo - Insufficient Authentication in Email Change Endpoint |
| CVE-2026-56252 | 5.4 MEDIUM | Capgo - Scope Isolation Failure in Webhook Test Endpoint |
| CVE-2026-56336 | 5.3 MEDIUM | Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint |
No comments yet