在 rcourtman Pulse 的 6.0.4 和 6.1.0-rc.4 及之前版本中,发现了一个安全漏洞。该漏洞影响了组件“Quick Security Setup Handler”中文件 /api/security/quick-setup 的 fmt.Sprintf 函数。对参数 Username 的操作导致输入验证不当,攻击者可能从远程发起攻击。建议升级受影响的组件以修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet