{"id":"CVE-2026-97063","published":"2026-09-25T19:17:59.267","lastModified":"2026-09-28T20:53:43.443","description":"X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-287"],"vendors":[],"products":[],"references":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/x-springboot/02_sms-code-account-takeover.py","tags":[]},{"url":"https://github.com/yzcheng90/X-SpringBoot","tags":[]},{"url":"https://github.com/yzcheng90/X-SpringBoot/blob/d74ddba989c0449948ff1ddb0d211b6a7ce81bfa/src/main/java/com/suke/czx/modules/sys/controller/SysLoginController.java#L94-L134","tags":[]},{"url":"https://www.vulncheck.com/advisories/x-springboot-through-6.0-authentication-bypass-via-login-code","tags":[]}],"exploitRefs":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/x-springboot/02_sms-code-account-takeover.py","tags":[]},{"url":"https://github.com/yzcheng90/X-SpringBoot","tags":[]},{"url":"https://github.com/yzcheng90/X-SpringBoot/blob/d74ddba989c0449948ff1ddb0d211b6a7ce81bfa/src/main/java/com/suke/czx/modules/sys/controller/SysLoginController.java#L94-L134","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows attackers to request login verification codes from unauthenticated endpoints, which can be read from HTTP responses and used to hijack user accounts.","exploitability":"Exploitation is relatively easy as attackers can request codes using known mobile numbers or email addresses without authentication.","blast_radius":"If exploited, attackers can hijack user accounts, potentially leading to unauthorized access and data breaches.","remediation":"Upgrade to X-SpringBoot 6.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","login","code-exposure"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:53:26.774Z"}}