Winter CMS 1.2.13 之前的版本中存在一个不完整的修复,涉及 System\\Twig\\SecurityPolicy 中 Twig 沙箱逃逸漏洞。该漏洞允许拥有模板编辑权限的已认证后端用户绕过沙箱限制。攻击者可以通过 Eloquent 模型和查询构建器中的方法转发(例如 saveQuietly()、deleteQuietly()、increment()、decrement() 和 newQuery())来读取和修改任意数据库记录,执行任意 SQL 语句,并通过在模板代码中注入 PHP 代码实现远程代
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet