References https://www.twcert.org.tw/tw/cp-132-8277-88b20-1.html https://www.twcert.org.tw/newepaper/cp-151-8277-88b20-3.html https://cve.imfht.com/detail/CVE-2024-11982?lang=en https://www.twcert.org.tw/tw/lp-132-1-9-20.html https://cve.imfht.com/detail/CVE-2024-11982
Related VulnerabilitiesPoCCVE-2026-62382: PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞大华智慧园区综合管理平台 backStoragePlan_deleteAll SQL注入漏洞PoCCVE-2026-45332: Automad < 2.0.0-beta.28 - Unauthenticated Admin Password Hash DisclosuremetaBase reset_password 接口存在sql注入漏洞PoCCVE-2026-44551: Open WebUI 'LDAP Empty Password' - Authentication BypassPoCCVE-2026-21484: AnythingLLM - Username Enumeration via Password RecoveryPoCCVE-2025-62512: Piwigo - User Enumeration via Password ResetPoCCVE-2026-2699: Progress ShareFile Storage Zones Controller - Authentication BypassProgress ShareFile Storage Zones Controller /ConfigService/Admin.aspx 权限绕过漏洞(CVE-2026-2699)BMC FootPrints /footprints/servicedesk/passwordreset/request/ 权限绕过漏洞(CVE-2025-71257/CVE-2025-71258/CVE-2025-71259/CVE-2025-71260)Gladinet CentreStack & Triofox /storage/filesvr.dn 文件读取漏洞(CVE-2025-14611)PoCCVE-2025-27506: NocoDB < 0.258.0 - Reflected XSS in Password Reset