Yzcheng90

X-springboot

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.29%
  • Veröffentlicht 25.09.2026 18:12:19
  • Zuletzt bearbeitet 28.09.2026 20:53:43

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or ...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 25.09.2026 18:12:19
  • Zuletzt bearbeitet 30.09.2026 18:18:44

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogi...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 25.09.2026 18:12:18
  • Zuletzt bearbeitet 29.09.2026 19:17:39

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords for any accou...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 25.09.2026 18:12:17
  • Zuletzt bearbeitet 29.09.2026 20:17:09

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS m...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 04.12.2025 00:00:00
  • Zuletzt bearbeitet 23.12.2025 00:19:47

This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (RBAC) through dual dependency on frontend menu systems and backend permission tables, without enforcing atomic synchronization betw...