Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Sanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in file
Vulnerability Description
A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the component Failed Login Handler. This manipulation of the argument errorPassword causes cleartext storage in a file or on disk. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
在文件或磁盘上的明文存储
Vulnerability Title
PublicCMS 安全漏洞
Vulnerability Description
PublicCMS是中国PublicCMS公司的一套使用Java语言编写的开源内容管理系统(CMS)。 PublicCMS 6.202506.d及之前版本存在安全漏洞,该漏洞源于对文件core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java中Failed Login Handler组件函数log_login的参数errorPassword的错误操作,可能导致明文存储。
CVSS Information
N/A
Vulnerability Type
N/A