maccmspro / maccms10

苹果cms-v10,maccms-v10,麦克cms,开源cms,内容管理系统,视频分享程序,分集剧情程序,网址导航程序,文章程序,漫画程序,图片程序
Apache License 2.0
645 stars 126 forks source link

后台存在ssrf漏洞 #22

Open Cedric1314 opened 1 year ago

Cedric1314 commented 1 year ago

Enter the background, click Collect --> Custom interface --> Interface address,

In the name box into payload1:http://7ca8e96e.dns.1433.eu.org.

It can cause ssrf attacks.

mac1 mac2 mac3 mac5 mac4