Sync in是Sync-in开源的一个服务器同步平台。 Sync in 1.1.1及之前版本存在安全漏洞,该漏洞源于FilesManager.saveMultipart和FilesManager.compress函数存在目录遍历问题,可能导致经过身份验证的攻击者获取系统读写权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-10712 | 7.3 HIGH | 07FLYCMS/07FLY-CMS/07FlyCRM login sql injection |
| CVE-2025-10707 | 6.3 MEDIUM | JeecgBoot sendMsg improper authorization |
| CVE-2025-10711 | 4.3 MEDIUM | 07FLYCMS/07FLY-CMS/07FlyCRM Login cross site scripting |
| CVE-2025-10710 | 4.3 MEDIUM | 07FLYCMS/07FLY-CMS/07FlyCRM index.php cross site scripting |
| CVE-2025-55910 | CmsEasy 安全漏洞 | |
| CVE-2025-57528 | Tenda AC6 安全漏洞 | |
| CVE-2025-57644 | Accela Automation Platform 安全漏洞 | |
| CVE-2025-57296 | Tenda AC6 安全漏洞 | |
| CVE-2025-56762 | KEOPS 安全漏洞 | |
| CVE-2025-57396 | Tandoor Recipes 安全漏洞 | |
| CVE-2025-54761 | PPress 安全漏洞 | |
| CVE-2025-54815 | PPress 安全漏洞 | |
| CVE-2025-52159 | PPress 安全漏洞 |
No comments yet