漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Function. This bypasses the initial check that uploaded files are image files. The application relies on frontend checks to restrict the administrator from changing the extension of uploaded files to .php. This restriction is easily bypassed with any proxy tool (e.g., BurpSuite). Once the attacker renames the file, and gives it the .php extension, a GET request can be used to trigger the execution of code on the server.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Vulnerability Type
未保护的候选通道
Vulnerability Title
InnoShop 安全漏洞
Vulnerability Description
InnoShop是InnoShop开源的一个基于 Laravel 11 的开源电子商务系统。 InnoShop 0.4.1及之前版本存在安全漏洞,该漏洞源于管理员面板文件管理器功能存在缺陷,可能导致代码执行。
CVSS Information
N/A
Vulnerability Type
N/A