脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE
脆弱性説明
baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory outside the theme directory, which may result in remote code execution (RCE). This issue has been patched in version 5.2.3.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
脆弱性タイプ
对路径名的限制不恰当(路径遍历)
脆弱性タイトル
baserCMS 安全漏洞
脆弱性説明
baserCMS是baserCMS团队的一套企业级内容管理系统(CMS)。 baserCMS 5.2.3之前版本存在安全漏洞,该漏洞源于主题文件管理API存在路径遍历,可能导致任意文件写入和远程代码执行。
CVSS情報
N/A
脆弱性タイプ
N/A