漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File Write
Vulnerability Description
OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content to with no validation that file_path stays within the ./core directory. A path-validation function, validate_file_path, exists elsewhere in the codebase (webserver/credentials.py) but is never invoked from compile_program, leaving the sink unprotected.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Thiago Alves OpenPLC 路径遍历漏洞
Vulnerability Description
Thiago Alves OpenPLC是Thiago Alves个人开发者的一款可编程逻辑控制器软件。 Thiago Alves OpenPLC存在路径遍历漏洞,该漏洞源于compile_program()函数在解析上传的Structured Text (.st)程序文件中的FILE指令时未验证文件路径是否在./core目录内,将内容写入任意文件系统路径,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A