Winter CMS 1.2.13 之前的版本中存在一个本地文件包含漏洞,该漏洞位于 JavascriptImporter 过滤器中。具有 cms.manage_assets 权限的已认证用户可以通过在主题 JavaScript 资源中放置 =include 或 =require 指令,泄露任意可由服务器读取的文件。攻击者可以引用主题目录之外的文件(例如 .env),通过 combine 路由提供的合并输出将被未认证的访问者读取,从而暴露应用程序密钥和数据库凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet