Backdrop CMS 1.35.1 之前的版本存在一个信息泄露漏洞,该漏洞允许未认证的攻击者获取在传输后留在服务器上的配置导出归档文件。攻击者可以下载具有配置导出权限的用户生成的压缩归档文件,从而获取完整的站点配置,包括敏感设置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet