Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
e107 CMS 2.3.0 Authenticated Remote Code Execution via Theme Upload
Vulnerability Description
e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Attackers can upload a crafted theme package through the theme.php endpoint that deploys a web shell to the e107_themes directory, then execute system commands via the payload.php script.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
e107 代码问题漏洞
Vulnerability Description
e107是E107团队的一套开源、免费且基于PHP和MySQL的内容管理系统(CMS)。该系统支持多种插件和外观主题,可作为个人博客、讨论社区、档案资料库等。 e107 2.3.0版本存在代码问题漏洞,该漏洞源于远程代码执行漏洞,允许具有主题安装权限的认证用户通过上传恶意主题文件执行任意命令,攻击者可以通过theme.php端点上传特制主题包,将Web shell部署到e107_themes目录,然后通过payload.php脚本执行系统命令。
CVSS Information
N/A
Vulnerability Type
N/A