References https://github.com/chaitin/xray-plugins/blob/main/poc/manual/nsfocus-uts-password-leak.yml https://cve.imfht.com/poc_detail/a89e9a860bdf658123e63ba5d3ed5a7e2cf5ca1a https://cve.imfht.com/poc_detail/a89e9a860bdf658123e63ba5d3ed5a7e2cf5ca1a?lang=en https://mygit.osfipin.com/release/31460110 https://www.ddosi.org/afrog/ https://cn-sec.com/archives/1325701.html https://gitextract.com/qi4L/qscan
Related VulnerabilitiesPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞PoCCVE-2026-45332: Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash DisclosuremetaBase reset_password 接口存在sql注入漏洞PoCCVE-2026-44551: Open WebUI 'LDAP Empty Password' - Authentication BypassPoCCVE-2026-21484: AnythingLLM - Username Enumeration via Password RecoveryPoCCVE-2025-62512: Piwigo - User Enumeration via Password ResetBMC FootPrints /footprints/servicedesk/passwordreset/request/ 权限绕过漏洞(CVE-2025-71257/CVE-2025-71258/CVE-2025-71259/CVE-2025-71260)PoCCVE-2025-27506: NocoDB < 0.258.0 - Reflected XSS in Password ResetPoCCVE-2025-56132: LiquidFiles < 4.2 - User Enumeration via Password ResetPoCCVE-2026-23760: SmarterTools SmarterMail - Admin Password ResetPoCSmarterMail /api/v1/auth/force-reset-password 权限绕过漏洞