Credential Exposure in yeqifu CarRental Druid Component
CVE-2025-9310
Key Information:
Badges
What is CVE-2025-9310?
A vulnerability has been identified in the yeqifu CarRental application, specifically in the Druid component's login.html file. This flaw allows attackers to manipulate certain functionalities, leading to the exposure of hard-coded credentials. The potential for exploitation exists, as the issue can be triggered remotely. Users of affected versions should take immediate action to mitigate risks, particularly as fixes may not be promptly available due to the product's rolling release nature.
Affected Version(s)
carRental 3fabb7eae93d209426638863980301d6f99866b3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved