reNgine 2.2.0 及更早版本在 GetFileContents API 端点存在一个授权绕过漏洞,允许任何已认证用户读取捆绑的重建工具(recon tool)的配置文件。拥有低权限 Auditor(审计员)角色的攻击者,可以在未进行基于角色的权限检查的情况下,通过查询该端点,访问包含 SecurityTrails、Shodan、Censys、VirusTotal、BinaryEdge 和 Hunter 等第三方服务 API 密钥的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yogeshojha | rengine | 0 ~ 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet