Brainstorm Force SureForms 版本(低于 2.1.3)中的 Entries 组件在处理及渲染过程中,未对用户可控的表单字段或提交内容实施充分限制,这使得远程攻击者可通过构造恶意表单提交,耗尽服务器资源,阻止管理员访问 Entries 界面,并触发 HTTP 500 错误。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet