漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
Vulnerability Description
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker-controlled Ruby expression in the field options command parameter, which is evaluated via instance_eval within an ERB view whenever a post edit page is rendered, achieving server-side code execution with web server process privileges.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
Owen Peredo Diaz CAMALEON CMS 代码注入漏洞
Vulnerability Description
Owen Peredo Diaz CAMALEON CMS是Owen Peredo Diaz个人开发者开源的一款内容管理系统。 Owen Peredo Diaz CAMALEON CMS 2.1.1版本至2.9.1版本存在代码注入漏洞,该漏洞源于允许具有custom_fields管理权限的用户通过select_eval自定义字段类型提供恶意表达式,在渲染编辑页面时通过instance_eval执行任意Ruby代码,实现服务器端代码执行。
CVSS Information
N/A
Vulnerability Type
N/A