X-SpringBoot 6.0 及更早版本在数据库种子数据中默认启用了一个硬编码的静态管理员登录验证码“172839”。未经验证的攻击者可以通过向 接口提交该公开的管理员验证码,并配合已知的邮箱地址或手机号码,以任意用户身份进行身份验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yzcheng90 | X-SpringBoot | 0 ~ 6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97063 | 9.1 CRITICAL | X-SpringBoot through 6.0 Authentication Bypass via Login Code |
| CVE-2026-97060 | 7.2 HIGH | X-SpringBoot through 6.0 Authorization Bypass via User Management |
| CVE-2026-100192 | 6.5 MEDIUM | X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint |
No comments yet