NivoCart 2.4.0 及之前版本存在任意文件上传漏洞,其文件管理器中的 端点在以下情况下未对文件扩展名进行有效验证: 1. 当用户指定新的文件名时; 2. 当 参数值大于或等于 2 时。 拥有仅查看权限的后台(back-office)访问权限的攻击者可以利用此漏洞,向可通过 Web 访问的 目录上传 PHP 文件,并执行这些文件,从而实现远程代码执行(RCE)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94107 | 8.1 HIGH | NivoCart through 2.4.0 Predictable Administrator Password Reset Token |
| CVE-2026-94105 | 5.3 MEDIUM | NivoCart through 2.4.0 Destructive Configuration Write via the Password Reset Controller |
No comments yet