目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-41290 PoC — FlatPress 安全漏洞

来源
关联漏洞
标题: FlatPress 安全漏洞 (CVE-2024-41290)
Description:FlatPress是FlatPress社区的一个基于Php无需数据库支持的博客建站系统。 FlatPress v1.3.1版本存在安全漏洞,该漏洞源于使用不安全的方法通过cookie的组件存储身份验证数据。
Description
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to > store authentication data
介绍
# CVE-2024-41290
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to  store authentication data

Additional Information:

FlatPress CMS version 1.3.1 insecurely stores authentication-related data, including usernames and hashed passwords, directly in client-side cookies. This practice exposes sensitive information to potential unauthorized access and manipulation by attackers.

Vendor of Product:

Insecure Storage of Authentication Data in Cookies

Affected Product Code Base:

FlatPress CMS version 1.3.1 - 1.3

Affected Component:

Cookie

Impact:

Usernames and hashed passwords are exposed in client-side cookies, which can be accessed or modified by unauthorized parties.

If an attacker gains access to these cookies, they can potentially impersonate users or decrypt hashed passwords offline

Discoverer:

Parag Bagul
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →