Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9jf-8h9g-xq6h

Опубликовано: 01 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authentication and retrieve the encrypted "password" and "salt". The password can then be obtained through brute-force cracking.

linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authentication and retrieve the encrypted "password" and "salt". The password can then be obtained through brute-force cracking.

EPSS

Процентиль: 24%
0.00083
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
nvd
7 месяцев назад

linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authentication and retrieve the encrypted "password" and "salt". The password can then be obtained through brute-force cracking.

EPSS

Процентиль: 24%
0.00083
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284