Nginx UI <= 2.3.7 - Unauthenticated Installer Exposure
Nginx UI 2.0.0 to 2.3.8 contains an authentication bypass caused by unauthenticated access to /api/install during first-run setup, letting remote attackers claim the initial admin account, exploit requires attacker to access the service before legitimate operator.
Nginx UIPoC 已收录
CVSS—