以下是该漏洞描述的中文翻译: Silverstripe UserForms 为 Silverstripe CMS 提供了一个可视化的表单构建器。在 6.0.0 至 6.4.8、7.0.7 和 7.1.1 之前的版本中,CMS 中 UserForms 邮件接收人的“主题”字段接受一个精心构造的载荷,该载荷可被解释为可执行的服务器端代码。拥有配置 UserForms 邮件接收人权限的已认证 CMS 用户可以利用“主题”字段在服务器上执行任意代码,从而危及系统的机密性、完整性和可用性。该问题已在 6.4.9、7.0.7
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| silverstripe | silverstripe-userforms | < 6.4.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet