在 mooSocial 3.2.4 及更早版本中发现了一个安全漏洞。该问题涉及对 /stores/all-products 文件的某些未知处理。通过操纵参数 rating 可导致 SQL 注入攻击。此漏洞可被远程利用。目前相关 exploit 已在公网上发布,可能被用于实际攻击。厂商早在披露前已被联系,但对此未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | mooSocial | 3.2.0 |
cpe:2.3:a:moosocial:moosocial:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105144 | 5.3 MEDIUM | Drogon Static File Router StaticFileRouter.cc route path traversal |
| CVE-2026-105137 | 5.0 MEDIUM | Laradock Build Process Dockerfile code download |
| CVE-2026-105156 | 3.7 LOW | YzmCMS MD5 system.func.php password weak password hash |
No comments yet