漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Croogo CMS Admin File Manager FileManager.php isEditable path traversal
Vulnerability Description
A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.php of the component Admin File Manager. This manipulation causes path traversal. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Croogo 路径遍历漏洞
Vulnerability Description
Croogo是Croogo组织开源的一套基于CakePHP框架开发的内容管理系统(CMS)。该系统提供内容类型可自定义为Blog、Node、Page,内容采用WYSIWYG编辑器编辑等功能。 Croogo 4.0.7及之前版本存在路径遍历漏洞,该漏洞源于Admin File Manager组件中FileManager.php文件的FileManager::isEditable函数存在路径遍历问题,可能导致远程攻击。以下版本受到影响:4.0.0版本、4.0.1版本、4.0.2版本、4.0.3版本、4.0.4
CVSS Information
N/A
Vulnerability Type
N/A