在 X-SpringBoot 6.0 及之前版本中,用户管理接口缺乏对象级别的授权控制,导致子管理员可以在未验证资源归属权的情况下修改或删除其他用户账户。拥有用户管理权限的攻击者可以通过 POST /sys/user/update 和 POST /sys/user/delete 接口重置任意账户(包括超级管理员)的密码、重新绑定角色或删除用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yzcheng90 | X-SpringBoot | 0 ~ 6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97063 | 9.1 CRITICAL | X-SpringBoot through 6.0 Authentication Bypass via Login Code |
| CVE-2026-97064 | 9.1 CRITICAL | X-SpringBoot through 6.0 Authentication Bypass via Static Master Code |
| CVE-2026-100192 | 6.5 MEDIUM | X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint |
No comments yet