该漏洞存在于ERP系统中,原因是身份认证控制不当以及API端点处的文件类型验证不足。未经身份验证的远程攻击者可以通过向目标系统的Web可访问目录上传任意文件来利用此漏洞。 成功利用该漏洞后,攻击者可以执行任意代码,从而入侵目标系统。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Manacle Technologies | Multi-tenant ERP System | version |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Manacle Technologies | Multi-tenant ERP System | version | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84148 | 9.2 CRITICAL | Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System |
| CVE-2026-84149 | 9.2 CRITICAL | Information Disclosure Vulnerability in Manacle Technologies ERP System |
No comments yet