216.73.216.197

CVE-2024-57432

· Published 31/01/2025 17:15 · Modified 18/02/2025 19:15

Labels: CVE-2024-57432 2025-01-31CVE-2024-57432CWE-863[email protected]

Essential information

Published
31/01/2025 17:15
Modified
18/02/2025 19:15
Author
Creator
CISA KEV
No
CWE

Description

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References