Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Rebuild proxy-download QiniuCloud.getStorageFile information disclosure
Vulnerability Description
A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to information disclosure. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252455.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Rebuild 信息泄露漏洞
Vulnerability Description
Rebuild是一个高度可定制化的企业管理系统。 Rebuild 3.5.5 及之前版本存在信息泄露漏洞,该漏洞源于/filex/proxy-download的QiniuCloud.getStorageFile函数存在安全问题,通过参数 url 导致信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A