zhinianboke xianyu-auto-reply HTTP Permission Trust Vulnerability in Payment Withdrawal Review Endpoint

Vulnerability

A vulnerability exists in the zhinianboke xianyu-auto-reply application, specifically within the backend Web API service. The issue arises in the payment withdrawal review endpoint, which is part of the application's financial transaction management. This vulnerability allows for unauthorized manipulation of withdrawal review actions, potentially leading to improper approval of withdrawal requests. The flaw can be exploited remotely, creating a risk of financial misconduct within the application.

Impact

Exploitation of this vulnerability allows for unauthorized approval of withdrawal requests, bypassing the intended verification process. This could lead to financial losses or misuse of funds within the application.

Reproduction

To reproduce this vulnerability, send a GET request to the '/api/v1/payment/withdraw/review' endpoint, including the 'id' parameter of the withdrawal record to be approved, the 'action' parameter set to 'approve', and a token parameter containing a valid but forgeable review token. The request will be processed as if it came from an authorized user, immediately approving the withdrawal.

Remediation

The vulnerability has been fixed in the latest commit. It is recommended to update to the version that includes this fix.

Added: Jul 15, 2026, 3:33 AM
Updated: Jul 15, 2026, 3:33 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
9.3
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.