漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.
Vulnerability Description
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unauthenticated attacker can traverse the filesystem to create arbitrary directories and write an index.yaml file containing attacker-controlled data. This vulnerability can lead to unauthorized modification of application behavior, potential data integrity issues, and service disruption in production environments. This vulnerability is fixed in 2.0.0-beta.2.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Grav 路径遍历漏洞
Vulnerability Description
Grav是Grav开源的一套可扩展的用于个人博客、小型内容发布平台和单页产品展示的CMS(内容管理系统)。 Grav 2.0.0-beta.2之前版本存在路径遍历漏洞,该漏洞源于FormFlash核心组件中的路径遍历,可能导致未经身份验证的攻击者通过操纵session_id遍历文件系统创建任意目录并写入包含攻击者控制数据的index.yaml文件。
CVSS Information
N/A
Vulnerability Type
N/A