SPIP 3.5.0 版本之前的 Crayons 插件存在一个授权缺失漏洞,未经身份验证的攻击者可以通过在 crayons_store.php 中省略 secu_(反伪造)参数,修改任意可编辑对象的字段,导致授权调度器无条件解析一个“始终为真”的处理程序,而不是执行正确的修改检查。攻击者可以利用此漏洞链式攻击:写入恶意的 .html 模板文件、泄露包含站点密钥的敏感配置文件,并伪造已签名的 AJAX 上下文以执行上传的模板,从而实现以 Web 服务器用户身份执行任意 PHP 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SPIP | SPIP Crayons Plugin | 0 ~ 3.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet