Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a crafted GET request sent to /commons/ip-location.
https://github.com/RacerZ-fighting/rebuild-vulns/blob/main/rebuild%203.7.7.md
https://github.com/RacerZ-fighting/CVE-vulns/blob/main/rebuild%203.7.5.md