Joomla 扩展 – regularlabs.com – Joomla 模块 Modules Anywhere 1.5.0 至 9.0.5 版本中存在本地文件包含(LFI)和服务端请求伪造(SSRF)漏洞。 Modules Anywhere Pro 允许在模块标签中添加额外的属性,用以替换所选模块的任意参数。受影响版本默认启用了此功能。然而,系统在使用这些替换值时,并未验证包含该标签的内容作者身份,即未进行任何来源或权限检查。该漏洞的实际安全风险取决于所选模块如何消费被替换的参数。 以 Joomla 核心提供的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| regularlabs.com | Modules Anywhere (Pro) extension for Joomla | 1.5.0-9.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet