cms icon indicating copy to clipboard operation
cms copied to clipboard

templatesAssetsEditor接口,依然存在任意文件读取漏洞

Open Mrgao1998 opened this issue 3 months ago • 2 comments

7.4.0版本中/api/admin/cms/templates/templatesAssetsEditor接口,依然存在任意文件读取漏洞

Image

Mrgao1998 avatar Sep 18 '25 06:09 Mrgao1998

收到,我们查一下,会尽快修复

starlying avatar Sep 26 '25 06:09 starlying

麻烦查到确实仍有这个漏洞的话,给我回个邮件,谢谢。

、Curry @.***

 

------------------ 原始邮件 ------------------ 发件人: "siteserver/cms" @.>; 发送时间: 2025年9月26日(星期五) 下午2:39 @.>; @.@.>; 主题: Re: [siteserver/cms] templatesAssetsEditor接口,依然存在任意文件读取漏洞 (Issue #3866)

starlying left a comment (siteserver/cms#3866)

收到,我们查一下,会尽快修复

— Reply to this email directly, view it on GitHub, or unsubscribe. You are receiving this because you authored the thread.Message ID: @.***>

Mrgao1998 avatar Sep 26 '25 06:09 Mrgao1998