phpIPAM 1.8.2 之前版本中的 REST API 存在一个身份验证绕过漏洞。攻击者可以利用不安全的对象缓存键机制,在未认证的情况下获得对 API 的完全访问权限。缓存仅根据查找值进行键值设置,而未包含所搜索的列。这使得在 app_id 查找过程中写入的缓存条目可以在后续的 app_code 查找中被满足,从而使攻击者能够使用数据库中的数字行标识符作为 API 令牌,对所有的 IP 地址管理记录进行读取、写入和删除操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet