totaljs / cms

Node.js Content Management System
http://www.totaljs.com/cms/
MIT License
228 stars 92 forks source link

There is an unauthorized vulnerability in totaljscms #44

Closed ainiy-top closed 9 months ago

ainiy-top commented 10 months ago

Upload the 1. txt file and click download

图片1

Copy the download link for 1. txt

图片2

Replace the Google browser with an administrator account that has not been logged in for access, and successfully download the file without authorization.

图片3

petersirka commented 10 months ago

Those files are public. What should it mean to make non-public files in CMS?