mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-06-20 09:50:49 +00:00
9 lines
399 B
Markdown
9 lines
399 B
Markdown
![]() |
# YApi Unauthorized Creation User And Mock RCE
|
||
|
|
||
|
Yapi is not authorized to create an account and can create a task in the background. Any command can be specified by the command parameter
|
||
|
|
||
|
**[FOFA](https://fofa.so/result?qbase64=YXBwPSJDaXRyaXgtQURDIg%3D%3D) query rule**: app="YAPI"
|
||
|
|
||
|
# Demo
|
||
|
|
||
|

|