在 Roskus Prospero Flow CRM 5.16.0 之前的产品照片上传功能中,存在“危险类型文件无限制上传”的漏洞。 拥有“创建产品”权限的已认证用户(通常为常规 Seller 角色)可以在应用源站内执行任意 JavaScript。 具体而言,照片校验规则仅根据文件内容(魔术字节/magic bytes)进行分类,且只拒绝固定的 PHP 扩展名列表;而 在保存文件时,直接使用客户端提供的扩展名作为存储文件名,并将文件复制到公共 Web 根目录。 如果一个文件以图像文件头开头,但携带 HTML 扩展名
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Roskus | Prospero Flow CRM | 0 ~ 5.16.0 |
cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet