QloApps 1.7.0 及之前版本中,admin/ajax.php 的 getEmailHTML 接口存在路径遍历漏洞,使得已认证的后台用户能够读取任意文件。攻击者可通过在 email 参数中提供相对路径序列来绕过目录限制,从而访问敏感文件,包括数据库凭据和配置数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet