具备后端管理员权限但不具备系统维护者(system maintainer)权限的用户,能够执行 、 和 这三个命令中的任意一个。这使得他们能够修改本应仅限于系统维护者才能操作的任意系统配置。由此可能导致,例如,获取系统维护者权限或引发服务拒绝(DoS)。利用此漏洞需要一个具有管理员级别的后端用户账户。该问题影响 TYPO3 CMS 14.2.0 至 14.3.6 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet