Record summary

CVE-2022-32430 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

io.github.talelin:lin-cms-core

Browse Maven / io.github.talelin:lin-cms-core
GitHub AdvisoryThrough 0.2.1affected

Nuclei templates

1
ProjectDiscoveryHIGHLin CMS Spring Boot - Default JWT TokenCVSS 7.5

An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.

Impact

Unauthenticated attackers can access backend administrative information and functions using a hardcoded default JWT token, potentially gaining complete control over the Lin CMS Spring Boot application including user management and content administration.

Remediation

Update Lin CMS Spring Boot to a version later than 0.2.1 that uses unique JWT secret keys, removes hardcoded tokens, and implements proper token rotation.

AuthorsDhiyaneshDK
Template tagscvecve2022lin-cmsauth-bypasstalelinvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:talelin:lin-cms-spring-boot:0.2.1:*:*:*:*:*:*:*
Shodan: http.html:"心上无垢,林间有风"
FOFA: body="心上无垢,林间有风"

Source: ProjectDiscovery

References

6