WebSocket 后端使用充电站标识符来唯一地关联会话,但允许使用相同会话标识符的多个端点建立连接。这种实现方式导致会话标识符具有可预测性。该漏洞可能使未授权用户能够以其他用户身份进行认证,或者使攻击者通过向后端发送大量有效的会话请求,从而造成拒绝服务(DoS)条件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-95102 | 9.4 CRITICAL | Monta monta.app Missing Authentication for Critical Function |
| CVE-2026-97363 | 7.5 HIGH | Monta monta.app Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-93474 | 6.5 MEDIUM | Monta monta.app Insufficiently Protected Credentials |
No comments yet