mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
18 lines
737 B
Markdown
18 lines
737 B
Markdown
### [CVE-2023-25403](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25403)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged with his username to bypass authentication.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/CleverStupidDog/yf-exam/issues/2
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|