RansomLook 在经过身份验证的 管理页面的 HTML 源代码中泄露了完整的 API 密钥。虽然界面仅显示每个密钥的简化表示形式,但完整的令牌被嵌入在由“启用/禁用”、“私有访问”和“删除”操作所使用的隐藏表单字段中。 因此,通过检查页面源代码或文档对象模型(DOM)即可恢复 API 凭据。此外,API 凭据还可能因调试代理、浏览器缓存、监控系统或其他中间组件在保留或检查 HTTP 响应体时而被无意泄露。攻击者若获取了其中一个令牌,便可利用该密钥所分配的权限进行认证,从而访问该密钥被授权访问的私有数据。 修补
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ransomlook | ransomlook | 0 ~ 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-78387 | 9.4 CRITICAL | RansomLook Missing Authorization in Web Configuration Editor Allows Application Configurat |
| CVE-2026-78372 | 9.2 CRITICAL | RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data |
| CVE-2026-78370 | 9.2 CRITICAL | RansomLook Unauthenticated Database Export Exposes Private Data |
| CVE-2026-78369 | 8.8 HIGH | Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook |
| CVE-2026-78391 | 8.8 HIGH | Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook |
| CVE-2026-78551 | 8.8 HIGH | RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authent |
| CVE-2026-78380 | 8.7 HIGH | Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLoo |
| CVE-2026-78386 | 8.7 HIGH | Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook |
| CVE-2026-78381 | 8.2 HIGH | RansomLook Arbitrary File Read via Path Traversal in Post screen Field |
| CVE-2026-78385 | 8.2 HIGH | RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local |
| CVE-2026-78553 | 7.0 HIGH | Insecure Flask Secret-Key File Permissions Allow Local Administrator Session Forgery in Ra |
| CVE-2026-78378 | 6.9 MEDIUM | Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data |
No comments yet