漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
Vulnerability Description
ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared Object.prototype.toString function's call property and cause a persistent process-wide denial of service until restart.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
CWE-1321
Vulnerability Title
Apostrophe Technologies ApostropheCMS 输入验证错误漏洞
Vulnerability Description
Apostrophe Technologies ApostropheCMS是Apostrophe Technologies公司开源的一个全栈内容管理系统。 Apostrophe Technologies ApostropheCMS 4.32.0及之前版本存在输入验证错误漏洞,该漏洞源于PATCH /api/v1/article/:id接口接受继承的路径toString.call并传递给apos.util.set()和apos.util.get(),允许已认证编辑者覆盖共享的Object.prototype
CVSS Information
N/A
Vulnerability Type
N/A