Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed via its URL, the server executes the PHP payload, enabling an attacker to run arbitrary system commands and achieve full compromise of the underlying host. This has been demonstrated by embedding a backdoor within a PDF and renaming it with a .php extension.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Badaso 安全漏洞
Vulnerability Description
Badaso是Uasoft开源的一个开源的 Laravel Vue 无头 CMS。 Badaso 2.9.11版本存在安全漏洞,该漏洞源于Media Manager允许上传含PHP代码的文件,可能导致任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A