在 commit b97dbaf 之前的 Issabel Framework(支撑 Issabel PBX 软件的 Web 框架)中,pbxapi 的 index.php 文件中包含一个硬编码的 HS256 JWT 签名密钥。该密钥在所有安装实例中均相同,这使得未认证的远程攻击者能够伪造有效的 Bearer 令牌。攻击者可以利用伪造的令牌调用 manager 的 originate 端点,并传入 System 应用参数,从而让 Asterisk 以 Asterisk 用户身份执行任意操作系统命令。据 Shadows
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Issabel Foundation | Issabel Framework | < b97dbaf0b71c1c36f841e672b664afbeb02773bd |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Issabel Foundation | Issabel Framework | 0 ~ b97dbaf0b71c1c36f841e672b664afbeb02773bd | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet