漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Craft CMS: Sensitive File Disclosure / Server-Side File Read
Vulnerability Description
Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and above, prior to 5.10.0, the dataUrl() Twig function is included in Craft’s Twig sandbox allowlist, allowing any control panel user granted the utility:system-messages permission to embed a file-reading payload into system email templates. When those emails are sent, the server reads the target file and returns its contents as a base64-encoded data URL embedded in the email body. The .env file, which typically contains the database password, CRAFT_SECURITY_KEY, and third-party API keys, passes all of Craft’s existing dataUrl() protection checks and is fully exfiltrated. Obtaining CRAFT_SECURITY_KEY enables an attacker to forge session tokens and escalate to full admin account takeover. This issue has been fixed in versions 4.18.0 and 5.10.0.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Craft CMS 信息泄露漏洞
Vulnerability Description
CraftCMS cms是CraftCMS的内容管理系统。 Craft CMS存在信息泄露漏洞,该漏洞源于dataUrl() Twig函数被列入Twig沙盒白名单,允许具有utility:system-messages权限的控制面板用户在系统邮件模板中嵌入文件读取有效载荷,导致服务器读取目标文件并以base64编码的数据URL返回文件内容,从而泄露.env文件中的数据库密码、CRAFT_SECURITY_KEY和第三方API密钥,获取CRAFT_SECURITY_KEY可导致攻击者伪造会话令牌并完全接管管
CVSS Information
N/A
Vulnerability Type
N/A