Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HAXCMS PHP has a File Upload Validation Bypass
Vulnerability Description
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functionality in HAXCMS PHP only validates file extensions using a regex pattern without checking the actual file content or MIME type. This allows attackers to upload malicious files (e.g., PHP webshells) disguised as legitimate image files, potentially leading to remote code execution. Version 25.0.0 contains a fix for the issue.
CVSS Information
N/A
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
HAX CMS PHP 代码问题漏洞
Vulnerability Description
HAXCMS是HAX The Web开源的一个内容管理系统。 HAX CMS PHP 11.0.6版本至25.0.0之前版本存在代码问题漏洞,该漏洞源于文件上传功能仅使用正则表达式验证文件扩展名而未检查实际文件内容或MIME类型,可能导致攻击者上传伪装成合法图像文件的恶意文件,实现远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A