FileRun 2026.3.0 之前的版本存在操作系统命令注入漏洞。该漏洞由 CLI.php 中对 的空操作(no-op)重定义引发,导致 shell 元字符的转义被移除,使得攻击者可控的输入未经净化便直接传递至 调用点(sink)。攻击者可通过以下两种路径利用该漏洞: 1. 交互式路径:通过 中精心构造的 参数进行利用,此路径需要超级用户身份验证。 2. 持久化路径:将恶意载荷存储在 或 字段中,当任意用户触发视频缩略图生成时,这些载荷会被执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73693 | 8.8 HIGH | FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler |
| CVE-2026-73698 | 7.2 HIGH | FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action |
| CVE-2026-73699 | 7.2 HIGH | FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms() |
No comments yet