在拥有合法用户凭据的情况下,攻击者可以构造恶意的 SQL 语句,绕过身份验证逻辑,直接执行任意的数据库查询。这进而会导致数据库查询变慢以及查询范围扩大。该漏洞的利用门槛低、影响范围广,无需外部权限提升即可利用,因此被归类为高优先级修复项。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet