漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE
Vulnerability Description
baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory outside the theme directory, which may result in remote code execution (RCE). This issue has been patched in version 5.2.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
baserCMS 安全漏洞
Vulnerability Description
baserCMS是baserCMS团队的一套企业级内容管理系统(CMS)。 baserCMS 5.2.3之前版本存在安全漏洞,该漏洞源于主题文件管理API存在路径遍历,可能导致任意文件写入和远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A