在 Taskview Community 1.56.0 之前版本中存在一个缺失身份验证的漏洞,该漏洞允许未经验证身份的攻击者注册任意 OAuth 客户端,并通过利用默认启用且无需身份验证的 OAuth 2.0 动态客户端注册端点,接管用户账户。攻击者可以向该注册端点发送 POST 请求,以获取 client_id 和 client_secret,然后构造指向攻击者控制的重定向 URI 的恶意授权链接,从而捕获授权码,并将这些授权码交换为访问令牌,进而获得对受害者账户数据的完整 API 访问权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gimanh | taskview-community | < 1.56.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Gimanh | taskview-community | 0 ~ 1.56.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet