nuxsmin sysPass是nuxsmin个人开发者的一款密码管理软件。 nuxsmin sysPass 3.2.11及之前版本存在授权问题漏洞,该漏洞源于JSON-RPC API中缺少对象级授权,允许API token持有者枚举账户元数据、覆盖密码和删除账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-65708 | 8.1 HIGH | sysPass 3.2.11 Insecure Direct Object Reference via AccountFileController |
| CVE-2026-65711 | 7.2 HIGH | sysPass 3.2.11 Authenticated OS Command Injection via Backup Path |
| CVE-2026-65710 | 7.1 HIGH | sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption |
No comments yet