漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Unrestricted Upload of File with Dangerous Type in SOPlanning
Vulnerability Description
SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate user.csv file alongside a malicious file, which is extracted on the server. When combined with CVE-2026-40547 (Path Traversal), the malicious file (e.g., a PHP script) can be placed in a web-accessible location and executed via the browser. This issue affects SOPlanning version 1.55 and below.
CVSS Information
N/A
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
SOPlanning 代码问题漏洞
Vulnerability Description
SOPlanning是SOPlanning公司的一套在线项目管理软件。 SOPlanning 1.55及之前版本存在代码问题漏洞,该漏洞源于未验证上传文件扩展名,可能导致经过身份验证的攻击者上传包含合法user.csv文件和恶意文件的ZIP存档,恶意文件可被放置在Web可访问位置并通过浏览器执行。
CVSS Information
N/A
Vulnerability Type
N/A