Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Eva4 安全漏洞
Vulnerability Description
Eva4是GoldPanKit开源的一套基于SpringBoot 2.x、Shiro、MyBatis Plus和knife4j等技术的权限管理基础工程,可与任意eva系前端结合使用来完成权限系统的研发。 Eva4 v4.1.0版本存在安全漏洞,该漏洞源于/api/resource/local/download端点的path参数可以下载任意文件。
CVSS Information
N/A
Vulnerability Type
N/A