Cherry-toto / jizhicms

极致CMS(以下简称:JIZHICMS)是一款开源免费,无商业授权的建站系统。
https://www.jizhicms.cn
MIT License
176 stars 40 forks source link

File allows malicious webshell code to be added #71

Closed Kagantua closed 2 years ago

Kagantua commented 2 years ago

Find the "Edit Template Online" plugin in the "Plugin Management" section of the backend administration, and proceed to install it.

image-20220509194416565

Turn on the switch for the plugin and configure it.

image-20220509194437706

image-20220509194455177

Then enter the file management interface.

image-20220509194512067

Open the index.php file, then add the webshell malicious code.

image-20220509194538555

Open the webshell management tool, enter the URL of the webshell and the corresponding connection password to connect.

image-20220509194602387

Successful connection.

image-20220509194627305

Cherry-toto commented 2 years ago

Thank you for your advice. It's not a security issue. It's the function of this plug-in! Thank you again!