HFS 2.4.0 及更早版本在 multipart 上传处理器中存在模板注入漏洞。未认证的攻击者可以通过在文件名中嵌入恶意模板语法,实现远程代码执行。攻击者可构造包含模板闭合引号序列后接 exec 宏的文件名,从而绕过分发器中的授权检查,在底层主机系统上执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97360 | 10.0 CRITICAL | HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine |
| CVE-2026-97362 | 7.5 HIGH | HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread |
No comments yet