ZFile 5.0.5 及以下版本在下载端点未能将请求的文件路径与共享链接中允许的条目进行有效校验。持有共享链接的攻击者可以通过查询参数指定任意文件路径,从而下载共享基础目录下的任意文件,从而绕过预设的访问限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet