baserCMS 5.3.0 之前的版本中存在一个 SQL 注入漏洞,该漏洞位于 BcDatabaseService.php 文件中。经过身份验证的管理员可以利用此漏洞,在序列更新、CSV 导出和表管理等操作中,直接将攻击者控制的表名和配置值注入到 SQL 语句中。 攻击者可以结合利用备份还原代码注入缺陷——该缺陷导致模式文件(schema files)中类定义之外的 PHP 代码在加载时无条件执行——从而植入恶意的表名,并触发基于错误信息的 SQL 注入攻击,进而获取 PostgreSQL 后端数据库的版本信息、
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| baserproject | basercms | < 5.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| baserproject | basercms | 0 ~ 5.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet