Blogbook是Chaitak Gorai个人开发者的一个内容管理系统项目。 Blogbook 92f5cf90f8a7e6566b576fe0952e14e1c6736513及之前版本存在代码注入漏洞,该漏洞源于文件/post.php中参数comment_author/comment_email/comment_content存在跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| chaitak-gorai | Blogbook | 92f5cf90f8a7e6566b576fe0952e14e1c6736513 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-5400 | 7.3 HIGH | chaitak-gorai Blogbook GET Parameter user.php sql injection |
| CVE-2025-5401 | 7.3 HIGH | chaitak-gorai Blogbook GET Parameter post.php sql injection |
| CVE-2025-5402 | 7.3 HIGH | chaitak-gorai Blogbook GET Parameter edit_post.php sql injection |
| CVE-2025-5403 | 6.3 MEDIUM | chaitak-gorai Blogbook GET Parameter view_all_posts.php sql injection |
| CVE-2025-5406 | 6.3 MEDIUM | chaitak-gorai Blogbook posts.php unrestricted upload |
| CVE-2025-5404 | 4.3 MEDIUM | chaitak-gorai Blogbook GET Parameter search.php denial of service |
| CVE-2025-5407 | 2.4 LOW | chaitak-gorai Blogbook register_script.php cross site scripting |
No comments yet