Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Unrestricted Upload of File with Dangerous Type vulnerability on Cockpit CMS from Agentejo
Vulnerability Description
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Agentejo Cockpit 代码问题漏洞
Vulnerability Description
Agentejo Cockpit是德国Agentejo公司的一款用于管理网站结构化内容的管理系统。 Agentejo Cockpit CMS v0.5.5 版本存在代码问题漏洞,该漏洞源于从 /media/api 处可以无限制上传文件。
CVSS Information
N/A
Vulnerability Type
N/A