Skip to content

There is login bypass in doracms #256

@dontblame

Description

@dontblame

There is login bypass in doracms2.18 and earlier versions. When logging in, you can bypass the login user authentication by replacing the return package with the return package after a system successfully logs in.
[Vulnerability proof]
Step 1:Log in to the system through the default account doracms and record the returned package.
image
Step 2:Use this return package to log in to other doracms systems.
image
image
Step 3:Successfully bypassed login to enter the system.
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions