在 Ech0 4.4.3 版本之前,/user 端点(用于 PUT 请求)受到 profile:read 权限范围的保护,该权限范围为只读权限。然而,系统却允许执行包括修改密码在内的写操作。具有管理员 profile:read 访问令牌的攻击者可以更改管理员的密码,并借此登录,从而获取一个不受任何权限范围限制的非受限会话令牌,以此绕过所有的权限范围强制执行机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79665 | 8.8 HIGH | Ech0 before 4.5.1 Authorization Bypass via Session Tokens |
| CVE-2026-79662 | 8.0 HIGH | Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass |
| CVE-2026-79659 | 7.7 HIGH | Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfo |
| CVE-2026-79667 | 7.6 HIGH | Ech0 before 4.4.3 Authentication Bypass via Scope Enforcement |
| CVE-2026-79658 | 7.5 HIGH | Ech0 before 5.0.1 Denial of Service via Accept-Language |
| CVE-2026-79664 | 7.4 HIGH | Ech0 before 4.7.3 Access Token Revocation Bypass |
| CVE-2026-79661 | 6.5 MEDIUM | Ech0 before 4.7.3 Unauthenticated fav_count Modification |
| CVE-2026-79666 | 6.5 MEDIUM | Ech0 before 4.4.3 Missing Authorization via dashboard log endpoints |
| CVE-2026-79672 | 5.5 MEDIUM | Ech0 before 4.4.3 Authentication Bypass via Comment Panel |
| CVE-2026-79671 | 5.5 MEDIUM | Ech0 before 4.4.3 SSRF via DNS Resolution Bypass |
| CVE-2026-79660 | 5.3 MEDIUM | Ech0 before 4.7.3 Email Disclosure via Public API |
| CVE-2026-79668 | 5.3 MEDIUM | Ech0 before 4.7.3 Unauthenticated Like Endpoint Metric Inflation |
| CVE-2026-79670 | 4.8 MEDIUM | Ech0 before 4.4.3 Stored XSS via SVG Upload |
| CVE-2026-79663 | 4.8 MEDIUM | Ech0 before 4.7.3 Stored XSS via RSS feed tag names |
| CVE-2026-79669 | 4.3 MEDIUM | Ech0 before 4.4.3 Missing Authorization on System Logs |
No comments yet