Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. This is possible because the application uses an unsanitized attacker-controlled parameter to construct an internal path.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OrangeScrum 路径遍历漏洞
Vulnerability Description
OrangeScrum是美国OrangeScrum公司的一款简单但功能强大的免费开源项目管理软件。 OrangeScrum 2.0.11版本存在安全漏洞,该漏洞源于其允许经过身份验证的攻击者从服务器删除任意本地文件。
CVSS Information
N/A
Vulnerability Type
N/A