FileRise 3.28.0 之前的版本存在一个权限提升漏洞,该漏洞允许已认证的较低权限攻击者通过利用 WebDAV 接口与 Web 应用会话上下文之间不当的会话隔离,获得未经授权的读取和写入访问权限。攻击者可以将有效的 Basic-Auth 凭据与一个处于激活状态的管理员 PHPSESSID Cookie 相结合,从而绕过授权边界。这是因为 WebDAV 层错误地从周围(ambient)Web 会话中继承了提升后的权限,而不是按照 RFC 4918 的要求,为每个请求执行独立的、无状态的认证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet