Evolution API 在 2.3.7 及以下版本中,其 中间件存在数组比较逻辑错误,导致比较结果始终为 false,从而允许未认证用户访问 端点。攻击者可以绕过 IP 白名单限制,获取敏感指标数据,包括服务器版本、数据库客户端名称、已配置的服务器 URL 以及 WhatsApp 实例详细信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| evolution-foundation | evolution-api | ≤ 2.3.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| evolution-foundation | evolution-api | 0 ~ 2.3.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet