Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any files on a SonicJS application, leading to Arbitrary File Write and Delete.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SonicJS 缓冲区错误漏洞
Vulnerability Description
SonicJS是Lane个人开发者的一个基于现代开源 NodeJs 的内容管理系统。 SonicJS 0.6.0版本及之前版本存在缓冲区错误漏洞,该漏洞源于文件覆盖。攻击者利用该漏洞可以写入和删除任意文件。
CVSS Information
N/A
Vulnerability Type
N/A