Veeam Service Provider Console是Veeam的云计算产品。 Veeam Service Provider Console 9.2及之前版本存在授权问题漏洞,该漏洞源于对密码重置功能中returnUrl参数处理不当,可能导致未认证攻击者控制生成的密码重置链接域名,当用户点击链接时重置码被发送到攻击者主机,从而接管账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Veeam | Service Provider Console | ≤ 9.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Veeam | Service Provider Console | 0 ~ 9.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet