A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/base.py of the component API Endpoint. The manipulation leads to missing authentication. The attack may be launched remotely.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://vuldb.com/?id.317012 | technical description vdb entry |
https://vuldb.com/?ctiid.317012 | signature permissions required |
https://vuldb.com/?submit.609040 | third party advisory |