zhinianboke xianyu-auto-reply
- <= dcb445ad97816ad65299a7580ee0c8c8f929da84
A vulnerability exists in the zhinianboke xianyu-auto-reply application, specifically within the backend user endpoint of the API. This vulnerability allows for unauthorized actions such as modifying user roles and statuses, bypassing CAPTCHA requirements, and manipulating withdrawal approval processes. The issue arises from several API endpoints that lack proper authentication and authorization checks, particularly those related to user management and financial transactions.
Exploitation of this vulnerability allows for unauthorized users to gain administrative privileges, manipulate user accounts, and interfere with financial workflows by approving withdrawals without proper authorization.
The vulnerability can be reproduced by sending requests to the affected API endpoints without the required authentication. For example, user enumeration can be done by accessing the '/api/v1/users/' endpoint, which should require authentication but does not. Similarly, an unauthenticated user can send a PATCH request to '/api/v1/users/{user_id}' to modify user details, including promoting a user to an administrator role. This can be done by including a valid access token in the request headers.
Users are advised to update to the latest version of zhinianboke xianyu-auto-reply, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.