Kirby 是一个开源内容管理系统。在 4.9.5 和 5.5.2 之前的版本中,Kirby 的媒体处理模块(位于 )允许 方法将带有路径的文件名拼接到经过校验的父级媒体目录中。在 Nginx、PHP 内置服务器或启用了 的 Apache 环境中,远程攻击者可以在文件名中提交编码后的斜杠字符(例如 ),从而遍历出父级媒体目录。对于存在的与不存在的缩略图配置,其响应差异会揭示任意 文件是否存在;而包含有效 键的 文件会导致所引用的图像被返回,并导致对应的任务文件被删除。此外,位于 中的 路径也接受 序列,允许访问预期
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71415 | 7.1 HIGH | Kirby: File upload permissions are not checked during processing of chunk data |
| CVE-2026-75592 | 6.9 MEDIUM | Kirby: Access to image files outside of the site root via path traversal in the media hand |
No comments yet