Record summary

CVE-2021-46371 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHAntD Admin - Sensitive Information DisclosureCVSS 7.5

AntD Admin has a security vulnerability that stems from Antd-admin 5.5.0 being affected by an incorrect access control vulnerability. Attackers can exploit this vulnerability to gain unauthorized access to some front-end interfaces, resulting in the leakage of sensitive information such as user IDs, names, ages, phone numbers, addresses, and more.

Impact

Unauthorized users can access sensitive information, leading to potential data leakage and privacy breaches.

Remediation

Update to the latest version of antd-admin that addresses access control issues.

WeaknessesCWE-306
Authorsritikchaddha
Template tagscvecve2021antdadmindisclosure
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Shodan: html:"/umi.js" html:"@@/devScripts.js"
FOFA: body="/@@/devScripts.js" && body="//! umi version:" && body="/umi.js"

Source: ProjectDiscovery

References

2