wxiaoqi Spring-Cloud-Platform OnlineController.java OnlineController.getOnlineInfo authorization
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.4%
probabilidad de explotación
0.4%top 72% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
wxiaoqi · Spring-Cloud-PlatformPoCs públicas encontradas — 1
cve_referencegithub.com/user-attachments/files/30627379/poc_vuln2_session_exposure.zipno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/user-attachments/files/30627379/poc_vuln2_session_exposure.ziphttps://github.com/wxiaoqi/Spring-Cloud-Platform/https://github.com/wxiaoqi/Spring-Cloud-Platform/issues/65https://vuldb.com/cve/CVE-2026-90595https://vuldb.com/submit/913789https://vuldb.com/vuln/403177https://vuldb.com/vuln/403177/cti