PT-2026-27633 · Ech0 · Ech0
Qiaonpc
·
Publicado
2026-03-24
·
Atualizado
2026-03-27
·
CVE-2026-33638
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ech0 versions prior to 4.2.0
Description
The
GET /api/allusers API endpoint is publicly accessible, allowing remote unauthenticated user enumeration and exposure of user profile metadata. The route is registered under public routes in internal/router/user.go:17 and is called using appRouterGroup.PublicRouterGroup.GET("/allusers", h.UserHandler.GetAllUsers()). Despite API documentation indicating an authentication requirement (@Security ApiKeyAuth), the endpoint does not enforce it. This allows unauthorized access to user data, potentially enabling account reconnaissance and targeted credential attacks.Recommendations
Update Ech0 to version 4.2.0 or later.
Exploit
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ech0