Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this functionality and control the server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sentrifugo 代码问题漏洞
Vulnerability Description
Sentrifugo是一套人力资源管理系统。该系统包括人力资源管理、绩效考核、招聘管理和资产管理等功能。 Sentrifugo 3.2版本存在安全漏洞,该漏洞源于用户可以在“Assets -> Add”标签下上传图片。此“上传图片”功能受到“不受限制的文件上传”影响,攻击者可利用该漏洞可以利用此功能上传恶意文件并控制服务器。
CVSS Information
N/A
Vulnerability Type
N/A