CVE-2021-46371
AntD Admin - Sensitive Information Disclosure
Record summary
CVE-2021-46371 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHAntD Admin - Sensitive Information DisclosureCVSS 7.5
AntD Admin has a security vulnerability that stems from Antd-admin 5.5.0 being affected by an incorrect access control vulnerability. Attackers can exploit this vulnerability to gain unauthorized access to some front-end interfaces, resulting in the leakage of sensitive information such as user IDs, names, ages, phone numbers, addresses, and more.
Impact
Unauthorized users can access sensitive information, leading to potential data leakage and privacy breaches.
Remediation
Update to the latest version of antd-admin that addresses access control issues.
Source: ProjectDiscovery