Cockpit CMS是Cockpit组织的一款内容管理系统。 Cockpit CMS 2.14.0及之前版本存在命令注入漏洞,该漏洞源于FFmpeg集成中未充分清理上传文件名,导致命令注入,可能允许仅具有assets/upload权限的认证用户通过上传包含shell元字符的视频文件执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cockpit HQ | Cockpit CMS | ≤ 2.14.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cockpit HQ | Cockpit CMS | 0 ~ 2.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet