nuxsmin sysPass是nuxsmin个人开发者的一款密码管理软件。 nuxsmin sysPass 3.2.11及之前版本存在授权问题漏洞,该漏洞源于不安全的直接对象引用,AccountFileController缺少授权检查,攻击者可通过提供任意数字文件ID枚举和操控保管库中的任何附件,绕过账户级访问控制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-65709 | 8.3 HIGH | sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API |
| CVE-2026-65711 | 7.2 HIGH | sysPass 3.2.11 Authenticated OS Command Injection via Backup Path |
| CVE-2026-65710 | 7.1 HIGH | sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption |
No comments yet