Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
Vulnerability Description
ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared Object.prototype.toString function's call property and cause a persistent process-wide denial of service until restart.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
CWE-1321
Vulnerability Title
Apostrophe Technologies ApostropheCMS 输入验证错误漏洞
Vulnerability Description
Apostrophe Technologies ApostropheCMS是Apostrophe Technologies公司开源的一个全栈内容管理系统。 Apostrophe Technologies ApostropheCMS 4.32.0及之前版本存在输入验证错误漏洞,该漏洞源于PATCH /api/v1/article/:id接口接受继承的路径toString.call并传递给apos.util.set()和apos.util.get(),允许已认证编辑者覆盖共享的Object.prototype
CVSS Information
N/A
Vulnerability Type
N/A