Логотип exploitDog
bind:CVE-2024-57432
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-57432

Количество 2

Количество 2

nvd логотип

CVE-2024-57432

около 1 года назад

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5ggv-wq69-w49q

около 1 года назад

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-57432

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-5ggv-wq69-w49q

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

CVSS3: 9.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу