DataEase < 2.10.10 contains a broken authentication caused by ineffective secret verification, letting users forge JWT tokens, exploit requires no special privileges.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view