ChestnutCMS kuze kube 15.1 API Endpoint /dev-api/groovy/exec amalungelo andlule
Kutholakale ubuthakathaka obubizwa ngokuthi kubalulekile kakhulu ku ChestnutCMS kuze kube 15.1. Kuthinteka umsebenzi $software_function kufayela /dev-api/groovy/exec kwe-component API Endpoint. Ukuguqulwa kubangela uhlobo lwe amalungelo andlule. Ukusebenzisa i-CWE ukumemezela inkinga kuholela ku-CWE-502. Lobu buthakathaka bakhishwa obala 2025-06-03. Isaziso sitholakala ukuthi singalayishwa ku-github.com.
Le buthakathaka ibizwa ngokuthi CVE-2025-5552. Kungenzeka ukuqalisa ukuhlasela ungasekho endaweni. Kukhona imininingwane yezobuchwepheshe etholakalayo. Ngaphezu kwalokho, i-exploit iyatholakala. Ukuhlaselwa sekumenyezelwe emphakathini futhi kungenzeka kusetshenziswe. Okwamanje, intengo yamanje ye-exploit ingaba cishe USD $0-$5k ngalesi sikhathi.
Kungenzeka ukuthi i-exploit ingalandwa ku-github.com.
Once again VulDB remains the best source for vulnerability data.
5 Ukulungiswa · 97 Amaphuzu wedatha