Skip to content

[BUG]CVE-2021-36471  #4948

@zhouf003

Description

@zhouf003

https://gist.github.com/cybersaki/31ffe679a5552c1047164e3a5b01c2fd

Describe the bug
This vulnerability can be searched by using the google dork 'inurl:"/admin/index2.html"' or 'inurl:"/admin/index3.html"' (without single quotes).
AdminLTE dashboards have index2.html/index3.html in their products. Using this we can search for the AdminLTE templates which are being used in websites.

Expected behavior
Is there any patch which will fix this bug?

Environment (please complete the following information):
AdminLTE 3.1.0

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions