Papermerge 3.5.3 存在远程代码执行漏洞。标准用户可通过对 /api/documents/upload 接口发起目录遍历攻击,向 site-packages 目录写入 Python .pth 文件。当 Python 解释器下次启动时,该文件中的代码将被自动执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Papermerge | Papermerge | 3.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet