漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover
Vulnerability Description
FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename and REGEX_FILE_NAME, which permit URL-encoded sequences (the regex blocks / and \ but not %).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
error311 FileRise 路径遍历漏洞
Vulnerability Description
error311 FileRise是error311的文件管理。 error311 FileRise 3.16.0之前版本存在安全漏洞,该漏洞源于上传端点对文件名验证不当,允许URL编码的路径分隔符绕过过滤,可能导致路径遍历和任意文件写入,进而导致管理员账户接管。
CVSS Information
N/A
Vulnerability Type
N/A