Ocsreports 管理接口 中的 CSV 文件上传功能存在未限制的文件上传漏洞。应用程序仅根据客户端提供的文件名进行验证,而未正确检查文件内容或安全地限制允许的文件类型。这使得具有管理员权限的用户能够将 PHP 文件上传到可通过 Web 界面访问的目录。如果该文件随后被服务器处理,攻击者即可执行任意代码,其权限等同于 Web 服务账户所具有的权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OCS Inventory NG | Ocsreports | 2.12.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OCS Inventory NG | Ocsreports | 2.12.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76178 | 9.2 CRITICAL | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76176 | 8.6 HIGH | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76175 | 8.6 HIGH | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76177 | 7.1 HIGH | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
No comments yet