Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Unrestricted Upload of File with Dangerous Type in Fernus LMS
Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Injection.This issue affects LMS: before 23.04.03.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Fernus Informatics LMS 代码问题漏洞
Vulnerability Description
Fernus Informatics LMS是土耳其Fernus公司的一个学习管理系统。 Fernus Informatics LMS 23.04.03之前版本存在代码问题漏洞,该漏洞源于存在无限制上传危险类型文件漏洞。攻击者利用该漏洞可以导致操作系统命令注入、服务器端包含(SSI)注入。
CVSS Information
N/A
Vulnerability Type
N/A