Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Sanluan PublicCMS templateResult API TemplateResultDirective.java execute special elements used in a template engine
Vulnerability Description
A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirective.java of the component templateResult API. This manipulation of the argument templateContent causes improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
CWE-1336
Vulnerability Title
PublicCMS 安全漏洞
Vulnerability Description
PublicCMS是中国PublicCMS公司的一套使用Java语言编写的开源内容管理系统(CMS)。 Sanluan PublicCMS 5.202506.d版本存在安全漏洞,该漏洞源于templateResult API组件中TemplateResultDirective.java文件的execute函数对参数templateContent处理不当,导致模板引擎中特殊元素中和不当。攻击者可能远程利用此漏洞。
CVSS Information
N/A
Vulnerability Type
N/A