Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Unauthenticated Remote Code Execution in SOY CMS
Vulnerability Description
SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
可信数据的反序列化
Vulnerability Title
SOY CMS 代码问题漏洞
Vulnerability Description
SOY CMS是一套内容管理系统(CMS)。 SOY CMS 3.0.2.327版本及之前版本存在安全漏洞。该漏洞源于没有任何限制地反序列化表单,攻击者可利用该漏洞远程代码执行(RCE)。
CVSS Information
N/A
Vulnerability Type
N/A