在 7.4.16 之前的 AlchemyCMS 以及 8.x 中 8.3.6 之前的版本中,GET /api/nodes 端点未对访问进行身份验证,这使得未认证的攻击者能够获取所有导航节点。攻击者可以在无需身份验证的情况下访问该端点,从而从所有站点和语言中披露受限页面的名称、URL 路径以及内部 URL。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AlchemyCMS | alchemy_cms | 0 ~ 7.4.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet