Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-50644. PoCs published by fushuling.
AI-analyzed exploit summary The document details an authentication bypass vulnerability in the blog software due to incorrect path handling in the `BaseInterceptor` class. Attackers can use `../` in the URI to bypass access controls and access admin APIs without authentication.
Description
zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.
Exploits (1)
The document details an authentication bypass vulnerability in the blog software due to incorrect path handling in the `BaseInterceptor` class. Attackers can use `../` in the URI to bypass access controls and access admin APIs without authentication.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H