PT-2026-99059 · Unknown · X-Springboot
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
X-SpringBoot versions prior to 6.0
Description
The software exposes
appKey and appSecret credentials via the 'GET /application/manager/select' endpoint. This occurs because the endpoint lacks authentication and field filtering, allowing unauthenticated attackers to retrieve these credentials. Consequently, an attacker can use this information to send arbitrary SMS messages through any tenant's SMS provider, which can lead to impersonation attacks and SMS bombing (sending a large volume of messages to a target to harass them).Recommendations
Update X-SpringBoot to a version later than 6.0.
As a temporary mitigation, restrict access to the 'GET /application/manager/select' endpoint.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
X-Springboot