漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Document root path disclosure on Maintenance page
Vulnerability Description
When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulnerability that could expose the installation path during build deployments. This information could be helpful to attackers if they are able to identify other exploitable vulnerabilities in the environment.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Adobe Magento Open Source和Magento Commerce 路径遍历漏洞
Vulnerability Description
Adobe Magento是美国奥多比(Adobe)公司的一套开源的PHP电子商务系统。该系统提供权限管理、搜索引擎和支付网关等功能。Magento Open Source是Magento的开源版本。Magento Commerce是Magento的商业版本。 Magento存在路径遍历漏洞,该漏洞源于不正确的授权检查。远程特权用户可以获得对其他受限制功能的未授权访问。攻击者可利用该漏洞获取敏感信息。以下产品及版本受到影响:Magento Open Source: 2.0.0, 2.0.1, 2.0.2,
CVSS Information
N/A
Vulnerability Type
N/A