在 FilePress(版本 3.0.1 及以下,具体编号为 zyx0814)中识别出一个漏洞。该漏洞影响 Publish 模块中 文件中一处未明确说明的代码。对参数 或 的操纵可能导致 SQL 注入攻击。该攻击可远程发起。利用代码已公开,可能已被实际利用。项目团队已提前通过问题报告获知此问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet