漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Maho Vulnerable to Authenticated Remote Code Execution via File Upload
Vulnerability Description
Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution. Version 25.9.0 fixes the issue.
CVSS Information
N/A
Vulnerability Type
依赖于外部提供文件的文件名或扩展名
Vulnerability Title
Maho 安全漏洞
Vulnerability Description
maho是MahoCommerce开源的一个电子商务平台。 Maho 25.9.0之前版本存在安全漏洞,该漏洞源于文件上传功能存在远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A