FacturaScripts 在 2026.7 版本之前存在一个 PHP 对象注入漏洞,该漏洞位于 WidgetSelect::processFormData() 函数中。攻击者(需要认证)可以通过向多个选择字段提交未设置 allowed_classes 过滤器的原始 POST 数据,触发 unserialize() 函数的执行。具体来说,攻击者可以提交一个序列化的 XLSXWriter 对象作为字段值,从而调用其 __destruct() 析构方法,删除任意指定文件(例如 config.php 或备份数据),导致
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NeoRazorX | facturascripts | 2025.7 ~ 2026.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet