Craft CMS 4.0.0-RC1 至 4.18.2 之前版本,以及 5.0.0-RC1 至 5.10.6 之前版本中,控制面板的元素搜索条件处理存在认证远程代码执行漏洞。在条件配置文件(condition.config)的 JSON 清理机制存在绕过漏洞,使得在 JSON 解码后,Yii 的行为/事件配置键被错误解释,从而导致以 PHP/Web 用户权限执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet