在 CodeAstro Online Job Portal 1.0 中发现了一个漏洞。受该漏洞影响的是文件 /users/update-profile.php 的某个未知功能。对参数 Name 进行操作可导致无限制的文件上传。攻击可以远程发起。该漏洞利用程序已公开,可能被攻击者使用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CodeAstro | Online Job Portal | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CodeAstro | Online Job Portal | 1.0 |
cpe:2.3:a:codeastro:online_job_portal:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet