在 4.10.11 版本之前的 LangBot 使用仅具有 24 位熵的密钥生成密码恢复密钥,并且对未认证的“重置密码”端点没有应用任何速率限制。知道管理员邮箱的远程攻击者可以通过向重置管理员密码的端点发送并发请求来遍历整个密钥空间,从而获得管理员账户的访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langbot-app | LangBot | 4.0.8.1 ~ 4.10.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet