← Back

Sa Token

sa-token

Vendor: Dromara • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dromara
1Sa Token
Nov 21, 2024
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.
1Dromara
1Sa Token
Nov 21, 2024
Oct 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.