References https://www.twcert.org.tw/tw/cp-132-7603-b1061-1.html https://www.twcert.org.tw/en/cp-139-7619-1f0b0-2.html https://www.klepb.klcg.gov.tw/tw/klepb1/3522-280398.html https://www.twcert.org.tw/tw/lp-132-1-17-20.html https://cve.imfht.com/detail/CVE-2023-48388?lang=en https://www.clouddefense.ai/cve/2023/CVE-2023-48388 https://cvefeed.io/vuln/detail/CVE-2023-48388
Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞PoCCVE-2026-56265: Crawl4AI < 0.8.7 - Hardcoded JWT Signing Key Authentication BypassPoCCVE-2026-45332: Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash DisclosuremetaBase reset_password 接口存在sql注入漏洞PoCCVE-2026-44825: Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials盛源|DMS+ (非行動端) - Use of Hard-coded Credentials博格資訊管理顧問|ERP App - Use of Hard-coded CredentialsPoCCVE-2026-44551: Open WebUI 'LDAP Empty Password' - Authentication BypassPoCCVE-2026-21484: AnythingLLM - Username Enumeration via Password RecoveryPoCCVE-2025-62512: Piwigo - User Enumeration via Password Reset