Required CVE Record Information
Description
A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVSS 4 Total
Score | Severity | Version | Vector String |
---|---|---|---|
2.3 | LOW | 4.0 | CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
5.0 | MEDIUM | 3.1 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
5.0 | MEDIUM | 3.0 | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
4.6 | — | 2.0 | AV:N/AC:H/Au:S/C:P/I:P/A:P |
Credits
- Unnlucky1 (VulDB User) reporter
References 4 Total
- vuldb.com: VDB-303136 | FastCMS JWT hard-coded key vdb-entry
- vuldb.com: VDB-303136 | CTI Indicators (IOB, IOC, TTP) signaturepermissions-required
- vuldb.com: Submit #543673 | 广州小橘灯信息科技有限公司 FastCMS 0.1.5 JWT hard coding leads to identity forgery third-party-advisory
- https://github.com/chujianxin0101/vuln/issues/2 exploitissue-tracking