Rybbit 在 2.7.0 之前版本存在 CORS 配置错误漏洞。该漏洞允许攻击者通过在 响应中反射任意请求源,从而绕过源站限制,且此时凭证(credentials)处于启用状态。攻击者可以从任意网站发起携带凭证的跨域请求,以受害者用户的身份读取分析数据、账户信息,并执行经过身份验证的状态变更操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet