OpenList 是一款支持多种存储方式的文件列表程序。在版本 4.2.4 之前, 文件中用于创建和更新共享的路径检查逻辑使用了 ,但未强制要求路径以目录分隔符作为边界。因此,拥有共享权限(CanShare)且基础路径(BasePath)为 的已认证用户,可以提交一个同级路径,例如 ,从而为超出权限范围的文件创建共享链接,并通过公开共享下载或列表处理程序读取指定目录之外的数据。该问题已在 4.2.4 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenListTeam | OpenList | < 4.2.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenListTeam | OpenList | < 4.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet