漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008
Vulnerability Description
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9. Drupal core contains a chain of methods that is exploitable when an insecure deserialization vulnerability exists on the site. This so-called gadget chain presents no direct threat but is a vector that can be used to achieve remote code execution if the application deserializes untrusted data due to another vulnerability.
CVSS Information
N/A
Vulnerability Type
CWE-915
Vulnerability Title
Drupal core 安全漏洞
Vulnerability Description
Drupal core是Drupal社区的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal core 7.0版本至7.102之前版本、8.0.0版本至10.2.11之前版本和10.3.0版本至10.3.9之前版本存在安全漏洞,该漏洞源于不受信任数据的反序列化,允许对象注入。
CVSS Information
N/A
Vulnerability Type
N/A