Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
Vulnerability Description
JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such as database credentials and encryption keys, and on versions 5.4.0 through 5.7.1, leverage registered Smarty modifiers including unserialize and file_get_contents to write a webshell to the web root and execute arbitrary commands as the web server user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1336
Vulnerability Title
JTL Software JTL Shop 代码注入漏洞
Vulnerability Description
JTL Software JTL Shop是JTL Software公司的一款电商系统软件 JTL Software JTL Shop 5.2.0及之前版本和5.4.0至5.7.1版本存在代码注入漏洞,该漏洞源于未清理用户输入导致服务器端模板注入,攻击者可能读取数据库凭据、加密密钥等敏感信息,在5.4.0至5.7.1版本中还可以写入webshell并执行任意命令。以下版本受到影响:5.2.0及之前版本和5.4.0至5.7.1版本。
CVSS Information
N/A
Vulnerability Type
N/A