Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
Vulnerability Description
Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, and packages/@tinacms/cli/src/next/vite/plugins.ts still routes POST /media/upload/* to mediaRouter.handlePost. The upload code in packages/@tinacms/cli/src/next/commands/dev-command/server/media.ts writes attacker-controlled multipart contents inside the configured media root. A remote attacker can cause a developer's browser to submit this state-changing request by inducing the developer to visit an attacker-controlled page while tinacms dev is running. This issue is fixed in version 2.5.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
TinaCMS 跨站请求伪造漏洞
Vulnerability Description
TinaCMS是Tina组织开源的一个内容管理系统。 TinaCMS 2.5.2之前版本存在跨站请求伪造漏洞,该漏洞源于CORS验证不当,对不允许的来源未正确拒绝请求,可能导致跨站请求伪造,攻击者可通过诱导开发者访问恶意页面,使浏览器提交上传请求,将恶意内容写入媒体根目录。
CVSS Information
N/A
Vulnerability Type
N/A