Flextype CMS 在 1.0.0-alpha.3 及之前版本中,Entries REST API 未能正确验证 和 参数,导致拥有 API 令牌的攻击者能够读取、创建或覆盖条目目录之外的文件。攻击者可在 API 请求中使用目录遍历序列,以跳出项目条目目录,从而操纵文件系统中的任意文件和目录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet