Insecure Permissions Vulnerability in Macrozheng Mall-Tiny Application
CVE-2024-57432
7.5HIGH
What is CVE-2024-57432?
The Macrozheng Mall-Tiny application version 1.0.1 contains a vulnerability due to insecure permissions stemming from its use of hardcoded JWT signing keys. These keys remain static, allowing for the potential manipulation of the JSON Web Tokens (JWTs) by malicious users. Specifically, user information is embedded directly into the JWT, which is subsequently used for privilege management. This design flaw facilitates forgery, enabling an attacker to bypass authentication for any user, ultimately undermining the application's security framework and user data integrity.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
