DoraCMS icon indicating copy to clipboard operation
DoraCMS copied to clipboard

There is login bypass in doracms

Open dontblame opened this issue 2 years ago • 1 comments

There is login bypass in doracms2.18 and earlier versions. When logging in, you can bypass the login user authentication by replacing the return package with the return package after a system successfully logs in. [Vulnerability proof] Step 1:Log in to the system through the default account doracms and record the returned package. image Step 2:Use this return package to log in to other doracms systems. image image Step 3:Successfully bypassed login to enter the system. image

dontblame avatar Jul 01 '22 05:07 dontblame

这个poc怎么写哦,怎么生成个长时间的admin_doracms与admin_doracms.sgi

xiahao90 avatar Aug 23 '22 08:08 xiahao90