No-CMS是Go Frendi Gunawan个人开发者的一个可自定义的内容管理框架。 No-CMS 1.0版本存在SQL注入漏洞,该漏洞源于manage_privilege导出端点的order_by参数存在SQL注入,可能导致经过身份验证的攻击者通过向/nocms/main/manage_privilege/index/export发送特制POST请求来操纵数据库查询并提取敏感数据库信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| goFrendiAsgard | No-CMS | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| goFrendiAsgard | No-CMS | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet