漏洞描述翻译: Admin3 在版本 3.0.0 及之前,在禁用用户账户时未能使现有会话失效,使得攻击者能够保留其原有的认证访问权限。攻击者可以继续使用在账户被禁用之前签发的 Bearer Token 来认证请求,因为 不会重新验证用户账户的锁定状态,并且会话过期时间会在每次请求时被重置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92918 | 8.8 HIGH | admin3 through 3.0.0 Session Token Disclosure via Audit Log |
| CVE-2026-92919 | 8.1 HIGH | admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename |
| CVE-2026-92921 | 4.9 MEDIUM | admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5 |
No comments yet