Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which is directly concatenated with the server's UPLOAD_PATH and passed to File.delete() without validation. A remote authenticated attacker can delete arbitrary files on the server by supplying directory traversal payloads.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Warehouse Management System 安全漏洞
Vulnerability Description
Warehouse Management System是Carlo Montero个人开发者的一个仓库管理系统。 Warehouse Management System 1.2版本存在安全漏洞,该漏洞源于未验证goodsimg参数,可能导致认证用户删除任意文件。
CVSS Information
N/A
Vulnerability Type
N/A