Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Spring SPEL Expression Language Injection
Vulnerability Description
Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H
Vulnerability Type
动态管理代码资源的控制不恰当
Vulnerability Title
Crafter CMS 安全漏洞
Vulnerability Description
Crafter CMS是一套面向数字体验应用程序的开源内容管理系统(CMS)。 Crafter CMS 存在安全漏洞,该漏洞源于具有Administrator或Developer角色的经过身份验证的用户可以在Spring bean中通过SPEL Expression执行操作系统命令。攻击者可利用该漏洞远程执行任意命令(RCE)。
CVSS Information
N/A
Vulnerability Type
N/A