Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses JavaScript to send requests to localhost port 5000, and the web browser is running on the same machine as the "lektor server" command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lektor 代码问题漏洞
Vulnerability Description
Lektor是Lektor开源的一个静态文件内容管理系统。 Lektor 3.3.10版本存在代码问题漏洞,该漏洞源于存在任意文件上传问题。
CVSS Information
N/A
Vulnerability Type
N/A