You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi, this is Tencent Xcheck team. Our code safety check tool Xcheck has found several unserialize vulnerabilities in this project(v4, v5, v6). It leads to remote code execution. Here are the details.
Hi, this is Tencent Xcheck team. Our code safety check tool Xcheck has found several unserialize vulnerabilities in this project(v4, v5, v6). It leads to remote code execution. Here are the details.
v6
line: 46
$this->rules = unserialize($this->request->post('rules', 'a:0:{}', ''));
line: 47
$this->ignore = unserialize($this->request->post('ignore', 'a:0:{}', ''));
v6 v5 v4
2. app/wechat/controller/api/Push.php
line: 102
$this->receive = $this->toLower(unserialize($this->request->post('receive', '', null)));
Prevent from abusing of this vulnerability, we don't provide proof of concept. We hope to repair it as soon as possible.
From Xcheck Team
The text was updated successfully, but these errors were encountered: