Filament 是一个用于加速 Laravel 开发的组件集。在 4.0.0 至 4.12.5 和 5.7.5 版本中, 文件在评估 权限检查之前,就先展示了多因素认证(MFA)挑战。对于被 拒绝访问面板的账户,如果提交正确的密码,系统会呈现 MFA 挑战界面;而提交错误密码则返回通用的认证失败提示。这使得未经身份验证的攻击者能够确认某个候选密码是否对该账户有效。当配置了基于电子邮件的 MFA 时,使用正确密码的路径还会向账户持有人发送登录验证码。该问题仅影响那些启用了 MFA 且被拒绝访问面板的账户。认证并未被
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| filamentphp | filament | >= 4.0.0, < 4.12.5 |
affected |
>= 5.0.0, < 5.7.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filamentphp | filament | >= 4.0.0, < 4.12.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet