Description
在 PrestaShop 的 tshirtecommerce(又名 Custom Product Designer)组件 2.1.4 中发现了一个问题。通过/tshirtecommerce/fonts.php 端点的 POST 参数 type,可以伪造 HTTP 请求,允许远程攻击者遍历系统目录以打开文件(对扩展名和路径无限制)。文件内容以 base64 编码返回。
在 PrestaShop 的 tshirtecommerce(又名 Custom Product Designer)组件 2.1.4 中发现了一个问题。通过/tshirtecommerce/fonts.php 端点的 POST 参数 type,可以伪造 HTTP 请求,允许远程攻击者遍历系统目录以打开文件(对扩展名和路径无限制)。文件内容以 base64 编码返回。
None yet. Search at https://trap.biu.life/?ref=rss