Datiphy 数据管理中心版本 v8.3.0 至 v8.5.1 的上传 API 接口存在外部控制文件名或路径的漏洞,远程攻击者可通过相对路径或绝对路径序列,将文件写入预期上传目录之外的任意位置。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Datiphy Inc. | Data Management Center | v8.3.0≤ v8.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Datiphy Inc. | Data Management Center | v8.3.0 ~ v8.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76156 | 9.4 CRITICAL | Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS |
| CVE-2026-76155 | 9.3 CRITICAL | Datiphy Data Management Center - Use of Default Credentials |
| CVE-2026-76157 | 8.8 HIGH | Datiphy Data Management Center - Missing Authentication for Critical Function |
No comments yet