A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access control which leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security.
https://github.com/anjoy8/Blog.Core
https://gist.github.com/Sw3092567023/c420c6a5ee947d72aeab2b3e0ba92a40