HashBrown CMS是HashBrown CMS组织的一款内容管理系统。 HashBrown CMS 1.4.6及之前版本存在命令注入漏洞,该漏洞源于Git deployer组件中GitDeployer.pullRepo()函数未对配置的分支值进行转义,直接拼接到shell命令中,可能导致攻击者通过恶意分支值执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashBrownCMS | hashbrown-cms | ≤ 1.4.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashBrownCMS | hashbrown-cms | 0 ~ 1.4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet