Kirby 是一个开源的内容管理系统。在 4.9.5 和 5.5.2 之前(具体取决于发布分支),Kirby 的媒体处理程序在 和 中使用了不完整的文件系统路径包含性检查,具体体现在 和 中。该检查会接受与目标根目录共享字符串前缀的兄弟目录(例如,位于 旁边的 ),因为它未要求路径末尾必须有目录分隔符边界或完全匹配。远程攻击者可以利用 在 PHP 可读的兄弟目录中创建并访问图像文件的缩略图(前提是该目录中包含有效的 缩略图任务文件),从而可能暴露 staging 站点、备份或其他内部站点,并在处理过程中删除该任务文
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75594 | 8.2 HIGH | Kirby: Access to image files and limited access to JSON files outside of the site root via |
| CVE-2026-71415 | 7.1 HIGH | Kirby: File upload permissions are not checked during processing of chunk data |
No comments yet