Filament 是一个用于加速 Laravel 开发的预构建全栈组件集合。在 4.0.0 至 4.12.6 以及 5.7.6 版本中, 中的 方法使用了由应用认证密钥(app authentication secret)和提交的 TOTP 代码共同派生的已使用代码缓存键。该实现通过“代码”而非“密钥”来隔离最近被接受的时间步长(timestep),导致在较新的代码已被使用后,先前签发的基于应用的多因素认证(MFA)代码仍可能被接受。虽然完全相同代码的重复使用已被阻止,但同一接受时间窗口内的其他代码仍然可用。 如果
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| filamentphp | filament | >= 4.0.0, < 4.12.6 |
affected |
>= 5.0.0, < 5.7.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filamentphp | filament | >= 4.0.0, < 4.12.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet