攻击者利用该漏洞可以将恶意压缩文件提供给用户下载并解压缩,就可以在系统上植入恶意软件或其他恶意代码,并对系统造成潜在的危害。
漏洞详细:https://github.com/dgarijo/Widoco/pull/551
修改代码:https://github.com/dgarijo/Widoco/commit/f2279b76827f32190adfa9bd5229b7d5a147fa92
CVE-2022-4772:https://nvd.nist.gov/vuln/detail/CVE-2022-4772
CNNVD-202212-4032:http://123.124.177.30/web/xxk/ldxqById.tag?CNNVD=CNNVD-202212-4032
Widoco < 1.4.17
Widoco >= 1.4.17
扫一扫订阅