Skip to content

目录/ss-admin/plugins/addLayerUpload/未登录都可以访问导致服务器被黑客攻击 #3865

@rendyu

Description

@rendyu

目录/ss-admin/plugins/addLayerUpload/未登录都可以访问 @starlying @sscmscom 需要尽快修复该问题
然后通过上传自己编辑的sscms.advertisement插件攻击服务器
sscms版本是7.3.1
攻击代码见附件
sscms.advertisement.zip

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions