X-SpringBoot 通过 6.0 版本存在安全漏洞。该漏洞表现为:在通过 GET /sys/mobile/code 和 GET /sys/email/code 等未经验证的端点请求时,系统会在 HTTP 响应中返回登录验证码,而不会将这些验证码发送给对应的账户持有人。攻击者可以利用已知的手机号码或电子邮件地址请求验证码,从响应中读取验证码,并通过 POST /sys/emailOrMobileLogin/login 接口以受害者身份进行认证,从而实现账户劫持。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yzcheng90 | X-SpringBoot | 0 ~ 6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97064 | 9.1 CRITICAL | X-SpringBoot through 6.0 Authentication Bypass via Static Master Code |
| CVE-2026-97060 | 7.2 HIGH | X-SpringBoot through 6.0 Authorization Bypass via User Management |
| CVE-2026-100192 | 6.5 MEDIUM | X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint |
No comments yet