zhinianboke xianyu-auto-reply Unauthenticated User Privilege Escalation Vulnerability

Vulnerability

A vulnerability exists in the zhinianboke xianyu-auto-reply application, specifically within the backend user endpoint of the API. This vulnerability allows for unauthorized actions such as modifying user roles and statuses, bypassing CAPTCHA requirements, and manipulating withdrawal approval processes. The issue arises from several API endpoints that lack proper authentication and authorization checks, particularly those related to user management and financial transactions.

Impact

Exploitation of this vulnerability allows for unauthorized users to gain administrative privileges, manipulate user accounts, and interfere with financial workflows by approving withdrawals without proper authorization.

Reproduction

The vulnerability can be reproduced by sending requests to the affected API endpoints without the required authentication. For example, user enumeration can be done by accessing the '/api/v1/users/' endpoint, which should require authentication but does not. Similarly, an unauthenticated user can send a PATCH request to '/api/v1/users/{user_id}' to modify user details, including promoting a user to an administrator role. This can be done by including a valid access token in the request headers.

Remediation

Users are advised to update to the latest version of zhinianboke xianyu-auto-reply, where this vulnerability has been addressed.

Added: Jul 15, 2026, 3:34 AM
Updated: Jul 15, 2026, 3:34 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
9.4
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.