Dolibarr 24.0.0(24.0.1 之前的版本)中存在一个针对 API 查询参数的大小写敏感拒绝列表绕过漏洞。该漏洞允许经过身份验证的攻击者通过提供受拒绝列表保护的字段的大写变体,来恢复受保护的数据库字段。攻击者可以利用数据库列解析的“大小写不敏感”特性,结合核心库中“大小写敏感”的拒绝列表检查,将前缀匹配谓词用作布尔预言机(Boolean Oracle),从而提取包括管理员账户在内的任意用户账户的完整密码哈希值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet