Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
Vulnerability Description
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value without rejecting a plugin’s own identifier or a descendant identifier. A staff user with plugin-change permission under CMS_PERMISSION can create a parent_id cycle in the plugin tree. The _get_descendants_cte and _get_ancestors_cte queries in cms/models/pluginmodel.py have no cycle guard, so get_descendants() and later rendering, copy, or delete operations can recurse indefinitely or reach a database recursion limit, corrupting the tree and consuming request workers. This issue is fixed in versions 5.0.8.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Vulnerability Type
未经控制的递归
Vulnerability Title
Django CMS Association django CMS 资源管理错误漏洞
Vulnerability Description
Django CMS Association django CMS是Django CMS Association组织的一个内容管理系统。 Django CMS Association django CMS 5.0.8之前版本存在资源管理错误漏洞,该漏洞源于move_plugin端点未正确验证plugin_parent值,可能创建循环引用,导致无限递归,消耗请求工作进程。
CVSS Information
N/A
Vulnerability Type
N/A