Guns 8.3.5 及更早版本中,SysUserController 存在信息泄露漏洞。由于 和 端点缺少 配置,权限拦截器会跳过对已认证用户的 RBAC 权限校验。因此,拥有任意有效登录令牌的攻击者可以获取系统中所有用户的敏感信息,包括:账户名、真实姓名、电子邮件地址、电话号码、最后登录 IP 地址以及角色分配信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet