Flextype CMS 在 v1.0.0-dev 及更早版本中存在表达式语言注入漏洞。持有有效 API 令牌的认证攻击者可以通过 POST /api/v1/query 端点,将未经过滤的用户输入传递给 Symfony ExpressionLanguage 引擎,从而读取任意文件。攻击者可以利用评估作用域中暴露的应用对象(包括 filesystem() 和 serializers())来读取服务器上的任意文件;如果能够通过次要向量将 PHP 文件写入磁盘,则可进一步实现有条件的远程代码执行(RCE)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet