Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

File upload to get webshell #21

Open
crazydeluobo opened this issue Mar 30, 2022 · 3 comments
Open

File upload to get webshell #21

crazydeluobo opened this issue Mar 30, 2022 · 3 comments

Comments

@crazydeluobo
Copy link

when you are in the background,you can upload a php file to get webshell。
1
2

@boiteasite
Copy link
Owner

Hi,
When you are in the background, you have admin rights. It can therefore be useful to be able to upload a PHP file to the server. I don't consider this to be a mistake.
Regards

@crazydeluobo
Copy link
Author

like the issues #19, It also need in the background , I think it need limit file suffix,Because the website administrator may disclose password 。

@boiteasite
Copy link
Owner

Hi,
You can't retrieve the password because it is hashed, not crypted.
Anyway, the one who is admin knows his password and CmsUno knows only one possible access, that of the admin.
The philosophy is not to restrict the capabilities of ADMIN unnecessarily.
If you want to change this, you have to edit the file uno/includes/elfinder/php/connector.php.
Regards

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants