Uptime Kuma - Installer
Detected Uptime Kuma setup page is publicly accessible with needSetup enabled, allowing unauthenticated users to complete installation and gain full admin access by access /setup-database.
Self-hosted website monitoring tool like "Uptime Robot".
共找到 4 条公开漏洞记录
Detected Uptime Kuma setup page is publicly accessible with needSetup enabled, allowing unauthenticated users to complete installation and gain full admin access by access /setup-database.
Uptime-Kuma before v1.23.0 is vulnerable to an information disclosure issue due to missing authorization on the /api/badge/1/ping/24 endpoint. An unauthenticated attacker can access this endpoint to leak ping statistics, such as average ping and ping history, for existing monitors without needing access to the protected status page. This can lead to unintended exposure of internal monitoring data.
Uptime Kuma has an Improper URL Handling vulnerability that can be exploited through the "real-browser" feature. By providing a URL using the file:/// protocol (e.g., file:///etc/passwd), an attacker can obtain a screenshot of local sensitive files, because the user input is not validated by the server.