在 liketrek TREK(3.0.22 及以下版本)中发现了一个漏洞。受影响的组件是“Pre-2FA mfa_token Handler”,具体位于文件 中的 函数。该漏洞会导致认证机制被绕过,从而引发不正确的身份验证结果。攻击者可以远程利用此漏洞。建议升级至版本 3.1.0 以修复此问题。同时,建议对受影响的组件进行升级。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78864 | 6.3 MEDIUM | liketrek TREK Journey Entry Update journey.controller.t journeyService.updateEntry sql inj |
| CVE-2026-78885 | 5.6 MEDIUM | liketrek TREK OIDC Service oidcService.ts findOrCreateUser improper authentication |
| CVE-2026-78886 | 3.7 LOW | liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal |
| CVE-2026-78887 | 3.7 LOW | liketrek TREK Journey Photo Proxy validateShareTokenForAsset authorization |
No comments yet