Camaleon CMS 从 2.7.5 到 2.9.1 版本在“从 URL 上传”媒体功能中获取远程文件时,未对重定向目标进行有效验证。经过身份验证的攻击者可以构造通过初始验证但随后重定向到内部网络地址的 URL,从而实现对内部服务的服务器端请求伪造(SSRF)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| owen2345 | CamaleonCMS | 2.7.5 ~ 2.9.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet