Pig 在 4.1.0 之前的版本中,/register/password 端点存在认证绕过漏洞:该端点会丢弃密码验证结果,因此当前密码可接受任意值。远程攻击者可通过提交一个用户名并配以错误的当前密码,覆盖任意账户的凭据(包括管理员账户),从而获得完全的管理员控制权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet