Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php
Vulnerability Description
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are unconditionally disabled across sendStream(), sendImageRequest(), send(), and fetchSearchHtml() with no option to re-enable verification. Attackers can perform man-in-the-middle interception to extract Authorization Bearer API keys from every AI request and inject crafted AI responses that may be acted upon by the tool-call execution pipeline, including the query_database and update_config tool handlers.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
证书验证不恰当
Vulnerability Title
emlog 加密问题漏洞
Vulnerability Description
emlog是emlog团队开源的一套基于PHP和MySQL的CMS建站系统。 emlog 2.6.23及之前版本存在加密问题漏洞,该漏洞源于TLS证书验证被禁用,可能导致网络邻近攻击者通过呈现任意TLS证书拦截出站HTTPS请求,实施中间人攻击,提取API密钥并注入特制AI响应。
CVSS Information
N/A
Vulnerability Type
N/A