Craft CMS是Craft CMS公司的一套内容管理系统(CMS)。 Craft CMS 5.8.0版本至5.10.13之前版本存在代码注入漏洞,该漏洞源于权限验证不当,仅拥有accessCp权限的远程已认证非管理员用户能够以PHP Web工作进程身份执行操作系统命令,可能导致远程命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet