疑似Oday
The Tolgee API exposes the `/v2/pats` endpoint without requiring authentication, allowing attackers to create Personal Access Tokens (PATs). These tokens can then be leveraged to interact with the API and gain elevated privileges.
id: tolgee-api-anonymous
info:
name: Tolgee API - Misconfiguration Anonymous Access
author: mat
...