Apostrophe Technologies ApostropheCMS是Apostrophe Technologies公司开源的一个全栈内容管理系统。 Apostrophe Technologies ApostropheCMS 3.6.2之前版本存在路径遍历漏洞,该漏洞源于import-export模块中的gzip.js根据攻击者控制的_id、name和extension字段构造附件源路径,未确保解析后的路径保持在解压附件目录内,可能导致经过身份验证的贡献者导入特制存档,读取具有允许扩展名的主机文件,
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| apostrophecms | apostrophe | < 3.6.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| apostrophecms | apostrophe | < 3.6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71553 | 7.1 HIGH | ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persisten |
| CVE-2026-63669 | 6.5 MEDIUM | ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-priv |
| CVE-2026-63670 | 6.1 MEDIUM | ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close |
No comments yet