75 Star 125 Fork 65

快乐源泉 / tpcms

 / 详情

ThinkPHP log information leak vulnerability exists in tpcms v3.2

待办的
创建于  
2021-07-01 14:02

Hello, after testing, I found that tpcms v3.2 has a vulnerability -- ThinkPHP log information leak.
Since the CMS code does not restrict the visitor's access to ThinkPHP's log directory, anyone can read ThinkPHP's Log through the URL. Such logs contain the administrator's user name, password, operation behavior, system information, etc. Sensitive information brings greater security risks to the system.

URL:
http://domain(or IP)/Data/Runtime/Logs/Admin/21_07_01.log
http://domain(or IP)/Data/Runtime/Logs/Home/21_07_01.log
http://domain(or IP)/Data/Runtime/Logs/Member/21_07_01.log

reference:
Image description

Image description

Image description

Image description

Image description

评论 (0)

xrun 创建了任务
xrun 关联仓库设置为快乐源泉/tpcms
展开全部操作日志

登录 后才可以发表评论

状态
负责人
里程碑
Pull Requests
关联的 Pull Requests 被合并后可能会关闭此 issue
分支
开始日期   -   截止日期
-
置顶选项
优先级
参与者(1)
PHP
1
https://gitee.com/happy_source/tpcms.git
git@gitee.com:happy_source/tpcms.git
happy_source
tpcms
tpcms

搜索帮助