Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-57432

Опубликовано: 31 янв. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:macrozheng:mall-tiny:1.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00128
Низкий

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.1
github
около 1 года назад

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

EPSS

Процентиль: 33%
0.00128
Низкий

7.5 High

CVSS3

Дефекты

CWE-287