Laranode 1.2.1 之前的版本在 POST /filemanager/upload-file 端点中存在路径遍历漏洞,允许经过身份验证的用户在其主目录之外写入任意文件。攻击者可以通过在 path 参数中提供目录遍历序列,将 PHP 文件写入其他租户的 Web 根目录,并模拟这些租户执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet