Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OneKeyAdmin 代码问题漏洞
Vulnerability Description
OneKeyAdmin是About 基于Thinkphp6+Element的插件化管理系统,网站、小程序、商城、CMS、APP、ERP、API接口一个系统全部搞定,无需脚手架开箱即用! OneKeyAdmin v1.3.9版本存在安全漏洞,该漏洞源于通过组件/admin1/config/update发现存在任意文件上传漏洞。攻击者利用该漏洞通过构造PHP文件执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A