anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Link | Tags |
---|---|
https://github.com/anji-plus/report/issues/7 | third party advisory exploit |
https://gitee.com/anji-plus/report/issues/I5VVZ0 | third party advisory exploit |