漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OS Command Injection Vulnerability and Potential Zip Slip Vulnerability
Vulnerability Description
There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted zip files which may execute arbitrary commands on the host operating system. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
baserCMS 操作系统命令注入漏洞
Vulnerability Description
baserCMS是baserCMS(Basercms)团队的一套企业级内容管理系统(CMS)。 baserCMS 的管理系统存在操作系统命令注入漏洞,具有上传文件权限的用户可以上传精心制作的 zip 文件,这些文件可以在主机操作系统上执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A