以下是该漏洞描述的中文翻译: 在 Concrete CMS 9.5.3 之前的版本中,系统会为 Stack(堆栈)、Container(容器)或布局区域中的每个子块注册视图资源,但未检查请求用户是否有权查看该子块。未认证的访客可以从任何嵌入了受影响 Stack、Container 或布局区域的公开页面中,恢复由受限制子块的资源注册所输出的配置值——例如站点配置的 Google Maps API 密钥——即使该子块在块级别有权限限制。任何其资源或页脚钩子会输出配置值的子块类型均受此影响。Concrete CMS 安全
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Concrete CMS | Concrete CMS | 5 ~ 9.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet