zhinianboke xianyu-auto-reply
- <= 04580d6490b4731d0055f29736930d8cc59b60d6
A vulnerability exists in the zhinianboke xianyu-auto-reply application, specifically within the backend Web API service. The issue arises in the payment withdrawal review endpoint, which is part of the application's financial transaction management. This vulnerability allows for unauthorized manipulation of withdrawal review actions, potentially leading to improper approval of withdrawal requests. The flaw can be exploited remotely, creating a risk of financial misconduct within the application.
Exploitation of this vulnerability allows for unauthorized approval of withdrawal requests, bypassing the intended verification process. This could lead to financial losses or misuse of funds within the application.
To reproduce this vulnerability, send a GET request to the '/api/v1/payment/withdraw/review' endpoint, including the 'id' parameter of the withdrawal record to be approved, the 'action' parameter set to 'approve', and a token parameter containing a valid but forgeable review token. The request will be processed as if it came from an authorized user, immediately approving the withdrawal.
The vulnerability has been fixed in the latest commit. It is recommended to update to the version that includes this fix.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.