### 漏洞概述 **漏洞名称**: Arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host **漏洞描述**: - 在 `ServeCreateOrUpdatePlaylist` 中存在…
### 漏洞概述 **标题**: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter **描述**: - **问题**: 在 `@microsoft/kiota-http-fetchlibrary` 的 `RedirectHandler`…
### 漏洞概述 **漏洞名称**: Path traversal in getPlaylist/deletePlaylist bypasses ownership check: any authenticated user can read or delete any other user's playlist **漏洞描述**: - 该漏洞允许任何已认证用户读取或删除其他用户的播放列表,包括管…
### 漏洞概述 该漏洞涉及PHAR反序列化,通过输出文件名绕过方案允许列表。具体来说,漏洞允许攻击者通过大小写不敏感的`phar:///`检查来绕过PHAR反序列化,从而在PHP isProtocolAllowed($filename)) { throw new \InvalidArgumentException(sprintf('The output file scheme is not su…