Gladys Assistant 5.1.0 之前的版本存在密码重置链接投毒漏洞。未经身份验证的远程攻击者可以利用 端点中由客户端提供的 参数,且该参数未经服务器端验证,从而获取任意账户的有效密码重置令牌。攻击者可以发送一个经过精心构造的请求,指定由攻击者控制的 值,导致受害者收到一个被投毒的重置链接,该链接会将会话令牌泄露给攻击者,从而实现完整的账户接管(包括管理员账户)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gladys Assistant | Gladys Assistant | < 5.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Gladys Assistant | Gladys Assistant | 0 ~ 5.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet