OpenSave 2.4.0 及更早版本在清单请求处理程序中未能正确验证由配对对等节点提供的保存路径。攻击者可以指定位于已配置保存位置之外的任意目录,从而通过清单和同步路由读取或写入文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet