漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE
Vulnerability Description
Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution through Craft::createObject().
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
Craft CMS 代码注入漏洞
Vulnerability Description
Craft CMS是Craft CMS公司的一套内容管理系统(CMS)。 Craft CMS 5.10.12之前版本存在代码注入漏洞,该漏洞源于对字符串类型字段布局元素清理不当,经过身份验证的控制面板用户可通过发布JSON字符串形式的字段布局选项卡元素绕过清理验证,注入Yii2行为附件和事件处理程序,从而触发任意对象实例化和代码执行。
CVSS Information
N/A
Vulnerability Type
N/A