Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/configuration, and import/create/fints.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Firefly III 信息泄露漏洞
Vulnerability Description
Firefly III是一套开源的个人财务管理系统。 Firefly III 4.7.17.3版本中存在信息泄露漏洞,该漏洞源于程序没有过滤file:///等协议的URLs。攻击者可利用该漏洞枚举本地文件。
CVSS Information
N/A
Vulnerability Type
N/A