pREST < 1.5.4 - SQL Injection Via Authentication Bypass
An authentication bypass vulnerability was introduced by changing the JWT whitelist configuration to use a regex pattern, allowing unauthorized access to any path containing /auth and leading to SQL Injection.
pRESTPoC 已收录
CVSS—