天下漏洞,尽知其名
MEDIUM

CVE-2026-102263 mwasikz robo-cafe-rms 文件上传漏洞

影响攻击者可远程上传恶意文件,可能导致服务器被控制

AI 研判

mwasikz robo-cafe-rms 的 manage-food.php 文件存在不受限制的文件上传漏洞。攻击者可远程利用该漏洞上传任意文件,且漏洞利用方式已被公开。厂商未对该披露作出回应。

影响范围

mwasikz robo-cafe-rms

受影响版本为 mwasikz robo-cafe-rms 至提交 228c44a02823f04e85db32b7137809a2856148fc。该产品采用滚动发布模式,无具体版本号信息。

漏洞详情

该漏洞属于不受限制的文件上传(Unrestricted Upload)类型,成因是 manage-food.php 中某未知函数未对上传文件的类型或内容进行有效校验。攻击者可构造恶意上传请求,将任意文件(如 WebShell)写入服务器,从而可能实现远程代码执行。

利用条件与风险

利用前提是攻击者能够访问 manage-food.php 相关上传接口,无需认证或仅需低权限。由于漏洞利用方式已公开,实战中被扫描和利用的风险较高。

修复建议

暂无官方修复方案,厂商未回应。临时缓解措施包括限制 manage-food.php 的访问权限、对上传文件类型进行白名单校验,或部署 WAF 拦截恶意上传请求。

原始情报

A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.