漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Capgo - Two-Factor Authentication Bypass via Organization Management API
Vulnerability Description
Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing organization details, inviting users) do not validate 2FA completion on the backend. An authenticated Admin user who has not enabled 2FA can replay or modify a previously captured ORG API request to perform privileged organization actions, bypassing the globally enforced 2FA requirement.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Vulnerability Type
服务端安全的客户端实施
Vulnerability Title
Capgo 处理逻辑错误漏洞
Vulnerability Description
Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在处理逻辑错误漏洞,该漏洞源于仅在用户界面层面执行强制双因素身份验证,敏感组织管理API端点未在后端验证双因素身份验证完成情况,可能导致已身份验证但未启用双因素身份验证的管理员用户重放或修改先前捕获的API请求来执行特权组织操作,绕过全局强制双因素身份验证要求。
CVSS Information
N/A
Vulnerability Type
N/A