漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Craft Potential Remote Code Execution via Twig SSTI
Vulnerability Description
Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-52293. This vulnerability has been patched in versions 4.16.6 and 5.8.7.
CVSS Information
N/A
Vulnerability Type
CWE-1336
Vulnerability Title
CraftCMS 安全漏洞
Vulnerability Description
CraftCMS是CraftCMS公司的一个内容管理系统。 CraftCMS 4.0.0-RC1至4.16.5版本和5.0.0-RC1至5.8.6版本存在安全漏洞,该漏洞源于Twig SSTI可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A