原文翻译: Admin3 在 3.0.0 之前的版本中,使用单轮 MD5 算法存储账户密码,仅以用户名作为盐值,且未使用密钥派生函数。由于计算开销极小,能够访问数据库的攻击者可以通过离线字典攻击或暴力破解,轻松还原出明文密码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92918 | 8.8 HIGH | admin3 through 3.0.0 Session Token Disclosure via Audit Log |
| CVE-2026-92919 | 8.1 HIGH | admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename |
| CVE-2026-92920 | 5.4 MEDIUM | admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled |
No comments yet