FileRun 版本 2026.3.0 之前存在 OS 命令注入漏洞,位于 PhotoProofSheet 处理器中。该漏洞允许拥有上传权限的认证用户通过上传文件名中含有 shell 元字符的文件,执行任意命令。攻击者可以上传文件名中包含命令替换语法(如反引号、分号或 $() 序列)的文件,然后触发 PhotoProofSheet 端点。由于在构造 ImageMagick montage 命令时缺少 过滤,任意命令将作为 web 服务器用户执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73698 | 7.2 HIGH | FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action |
| CVE-2026-73699 | 7.2 HIGH | FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms() |
| CVE-2026-73694 | 7.2 HIGH | FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition |
No comments yet