changedetection.io <= 0.53.9 存在路径遍历漏洞(CVE-2026-25527)

2026-06-08 changedetection.io PoC No

Description

changedetection.io <= 0.53.9存在路径遍历漏洞,由于对/static/<group>/<filename>路由中的'group'参数验证不当,使未授权攻击者能够读取本地应用程序源文件。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities