RansomLook 在处理与群组帖子(group posts)关联的 字段时存在路径遍历漏洞。 API 处理器将数据库控制的 值与应用程序的 目录直接拼接,并在未验证解析后的文件是否仍位于预期目录内的情况下直接打开该路径。 由于 字段是自由格式的,既可以通过管理后台的帖子编辑器进行填写,也可以从远程 RansomLook 实例导入的数据中填充,因此恶意的上游实例可以注入诸如 等路径遍历序列。当受影响的帖子随后通过 API 被检索时,RansomLook 会解析并读取攻击者控制的路径,并将所引用文件的内容以 Bas
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ransomlook | ransomlook | 0 ~ 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-78387 | 9.4 CRITICAL | RansomLook Missing Authorization in Web Configuration Editor Allows Application Configurat |
| CVE-2026-78555 | 9.4 CRITICAL | RansomLook API Key Disclosure Through /admin/apikeys HTML Source |
| CVE-2026-78372 | 9.2 CRITICAL | RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data |
| CVE-2026-78370 | 9.2 CRITICAL | RansomLook Unauthenticated Database Export Exposes Private Data |
| CVE-2026-78369 | 8.8 HIGH | Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook |
| CVE-2026-78391 | 8.8 HIGH | Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook |
| CVE-2026-78551 | 8.8 HIGH | RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authent |
| CVE-2026-78380 | 8.7 HIGH | Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLoo |
| CVE-2026-78386 | 8.7 HIGH | Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook |
| CVE-2026-78385 | 8.2 HIGH | RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local |
| CVE-2026-78553 | 7.0 HIGH | Insecure Flask Secret-Key File Permissions Allow Local Administrator Session Forgery in Ra |
| CVE-2026-78378 | 6.9 MEDIUM | Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data |
No comments yet