以下是该漏洞描述的中文翻译: LibreNMS 26.8.0 之前的版本在 REST API 中存在一个认证绕过漏洞。未认证的 attackers 可以通过发送数值而非字符串令牌来访问受保护的端点。攻击者可以利用 MySQL 的类型强制转换特性,通过发送 0 到 9 之间的小整数来匹配令牌哈希值,从而获得 API 功能的访问权限,包括设备凭证和管理功能,这些功能可通过告警模板实现远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet