xiaomlove / nexusphp

A private tracker application base on NexusPHP
https://nexusphp.org
GNU General Public License v2.0
845 stars 176 forks source link

An IMPORTANT security patch 重要安全补丁 #188

Closed Rey50 closed 1 year ago

Rey50 commented 1 year ago

1.user_can() 函数 游客越过鉴权的问题 (影响范围1.7~1.8) 2.ajax.php 任意执行漏洞 此patch为重要安全漏洞,已出现大范围利用攻击,请务必更新

English Version:

  1. The user_can() function allows guests to bypass the authentication process (influenced version 1.7~1.8)
  2. ajax.php arbitrary execution vulnerability This patch is an important security patch, and there has been a large-scale exploit attack, please upgrade to newest release immediately