ContiNew 的管理界面未能对多部件上传(multipart upload)端点实施文件上传权限检查或文件类型白名单验证,导致经身份认证的用户能够存储任意扩展名的文件。攻击者可以初始化分块上传、发送文件片段并完成上传,从而在后端存储中留下可通过 Web 服务器 URL 直接访问的任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| continew-org | continew-admin | ≤ 4.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| continew-org | continew-admin | 0 ~ 4.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet