LogicalDOC Enterprise 版本 ≤ 9.1.1 在工作流数据 Servlet(WorkflowsDataServlet)组件中存在盲 SQL 注入漏洞,攻击者可利用精心构造的工作流模板名称操纵 SQL 查询,从而实施注入攻击。该漏洞允许经过身份验证的用户执行恶意 SQL 操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105571 | 7.3 HIGH | PickMall Lilishop Mobile Binding bindMobile improper authorization |
| CVE-2026-105707 | 5.3 MEDIUM | uptrace user_handler.go Login information exposure |
| CVE-2026-105708 | 4.3 MEDIUM | imgproxy SVG svg.go sanitizeElement cross site scripting |
| CVE-2026-105572 | 4.3 MEDIUM | PickMall Lilishop Buyer Invoice List receipt authorization |
| CVE-2026-77178 | Oracle VM VirtualBox 堆外写漏洞 | |
| CVE-2026-95153 | Bludit CMS 3.22.0信息泄露漏洞 | |
| CVE-2026-95140 | kkFileView 5.0.0-5.0.2目录遍历漏洞 | |
| CVE-2025-71384 | Dbit WIFI4 N300 v1.0.0堆溢出允许执行OS命令 | |
| CVE-2025-71383 | Dbit WIFI4 N300 v1.0.0管理界面JSON解析导致崩溃漏洞 |
No comments yet