Rodauth 2.47.0 之前版本存在跨站请求伪造(CSRF)保护绕过漏洞,位于 JSON 请求内容类型验证环节。攻击者可以构造包含 子串的跨源表单提交,从而绕过 CSRF 令牌验证,并诱导受害者登录到攻击者控制的账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jeremyevans | rodauth | 0 ~ 2.47.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82466 | 8.7 HIGH | Rodauth before 2.46.0 Authentication Bypass via webauthn_login |
| CVE-2026-82469 | 5.4 MEDIUM | Rodauth before 2.47.0 Authentication Bypass via jwt_refresh |
| CVE-2026-82470 | 5.4 MEDIUM | Rodauth before 2.47.0 TOTP Code Reuse via Drift Window |
| CVE-2026-82467 | 4.7 MEDIUM | Rodauth before 2.47.0 Open Redirect via Return-to Path |
No comments yet