这段漏洞描述信息可以翻译为: Ransomlook 存在一个 Redis 全局模式注入漏洞,其原因是将用户控制的输入合并到 Redis SCAN MATCH 模式之前,没有进行足够的净化处理。 /api/health/<name> 端点尝试解析所提供的名称以匹配已知的群组或市场,但当解析失败时,它会回退到直接使用攻击者控制的值作为 Redis 键模式。因此,未认证的攻击者可以提供类似 、 、 或 这样的 Redis 全局元字符,从而扩展 SCAN 操作的范围,超出预期的群组限制。例如,请求 可以枚举所有群组和市场(
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ransomlook | ransomlook | ≤ 2.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ransomlook | ransomlook | 0 ~ 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78387 | 9.4 CRITICAL | RansomLook Missing Authorization in Web Configuration Editor Allows Application Configurat |
| CVE-2026-78555 | 9.4 CRITICAL | RansomLook API Key Disclosure Through /admin/apikeys HTML Source |
| CVE-2026-78372 | 9.2 CRITICAL | RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data |
| CVE-2026-78370 | 9.2 CRITICAL | RansomLook Unauthenticated Database Export Exposes Private Data |
| CVE-2026-78369 | 8.8 HIGH | Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook |
| CVE-2026-78391 | 8.8 HIGH | Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook |
| CVE-2026-78551 | 8.8 HIGH | RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authent |
| CVE-2026-78380 | 8.7 HIGH | Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLoo |
| CVE-2026-78386 | 8.7 HIGH | Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook |
| CVE-2026-78381 | 8.2 HIGH | RansomLook Arbitrary File Read via Path Traversal in Post screen Field |
| CVE-2026-78385 | 8.2 HIGH | RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local |
| CVE-2026-78553 | 7.0 HIGH | Insecure Flask Secret-Key File Permissions Allow Local Administrator Session Forgery in Ra |
No comments yet