Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a filename in silverstripe/assets via the AssetControlExtension.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SilverStripe 信息泄露漏洞
Vulnerability Description
SilverStripe是新西兰SilverStripe公司的一套开源的编程框架和内容管理系统 (CMS)。该系统具有支持多国语言、跨平台等特点。 SilverStripe 4.3.3及之前版本中存在安全漏洞,该漏洞源于程序没有对通过Upload::loadIntoFile()上传的受保护文件进行正确的访问控制。攻击者可利用该漏洞猜测silverstripe/assets中的文件名。
CVSS Information
N/A
Vulnerability Type
N/A