Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
nbnbk 代码问题漏洞
Vulnerability Description
nbnbk是基于thinkphp5的cms管理系统,B2C电商开源php商城系统平台,tp5开源cms,thinkphp企业网站源码,适合博客、中小企业建站二次开发。 nbnbk 3版本中存在安全漏洞,该漏洞源于getFileBinary 函数允许攻击者通过将任意 URL 注入 URL 参数来强制应用程序发出任意请求。
CVSS Information
N/A
Vulnerability Type
N/A