BookStack 在 26.05.4 之前版本中存在一个远程代码执行(RCE)漏洞,位于便携式 ZIP 导入功能中。拥有“导入内容”和“创建书籍”权限的用户可以上传一个 PHP 多态(polyglot)文件作为书籍封面。攻击者可以通过在 ZIP 归档中嵌入一个带有 文件名的 PHP 文件,从而绕过图像扩展名校验;该文件将被存储在公共 Web 根目录下,并可通过未认证请求执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bookstackapp | bookstack | 0 ~ 26.05.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet