漏洞描述 Prizm Content Connect中存在任意文件上传漏洞,该漏洞源于上传之前程序没有充分验证文件。攻击者利用该漏洞在受影响计算机中上传任意文件,导致在受影响应用程序上下文中执行任意代码。Prizm Content Connect 5.1版本中存在漏洞,其他版本也可能受到影响。
相关漏洞推荐 SmarterMail ConnectToHub /api/v1/settings/sysadmin/connect-to-hub 命令执行漏洞(CVE-2026-24423) Jeecg JimuReport /jmreport/testConnection 代码执行漏洞(CVE-2025-66913) POC wp-ssl-insecure-content-fixer-fpd: WordPress Plugin SSL Insecure Content Fixer - Full Path Disclosure POC wp-table-of-contents-plus-fpd: WordPress Table of Contents Plus - Full Path Disclosure POC wp-toc-plus-fpd: WordPress Plugin Table of Contents Plus - Full Path Disclosure POC wp-ssl-insecure-content-fixer-fpd: WordPress Plugin SSL Insecure Content Fixer - Full Path Disclosure POC CVE-2022-28666: Custom Product Tabs for WooCommerce < 1.7.8 - Unauthenticated Toggle Content Setting Update POC weak-csp-detect: Weak Content Security Policy - Detect 孚盟云CRM /Ajax/GetDropDownListContent.ashx SQL 注入漏洞 (CVE-2025-62712) JumpServer ConnectionToken 权限验证不当漏洞 孚盟云 GetDropDownListContent.ashx 存在SQL注入漏洞 POC 孚盟云 GetDropDownListContent.ashx SQL注入漏洞 CVE-2019-11510: Pulse Connect Secure SSL VPN Arbitrary File Read