在 blackms aistack 1.6.1 及更早版本中发现了一个漏洞。该问题影响组件 Static File Handler 中 文件的某个未知功能。对参数 的操纵会导致路径遍历(Path Traversal)。该攻击可远程执行。利用该漏洞的方法已公开,可能会被人利用。项目维护方已提前通过问题报告得知此问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet