Gorse < 0.5.10 - Unauthenticated Database Dump
Gorse < 0.5.10 contains an authentication bypass caused by empty admin_api_key in /api/dump and /api/restore endpoints, letting unauthenticated remote attackers access and modify protected data, exploit requires default empty admin_api_key configuration.
GorsePoC 已收录
CVSS—