这段文字描述了一个特定的安全漏洞,主要涉及 HTML 报告生成时的编码问题。为了保持技术术语的准确性,同时确保中文表达自然流畅,我进行了如下翻译: MongoSQL 过渡就绪工具(Transition Readiness Tool)将从 BI 连接器(BI Connector)日志文件中读取的查询文本和用户名写入其生成的 HTML 报告,但未针对该输出上下文进行编码处理。能够通过 BI 连接器发出查询的用户可以影响日志内容,使得查询中提供的标记(markup)在操作员稍后生成并打开该报告时,会被浏览器解析执行。这可
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MongoDB | BI Connector Transition Readiness Report | 1.0.0< 1.1.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB | BI Connector Transition Readiness Report | 1.0.0 ~ 1.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81532 | 8.8 HIGH | BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corrupt |
| CVE-2026-77586 | 8.0 HIGH | MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output |
| CVE-2026-81490 | 7.7 HIGH | MongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of |
| CVE-2026-81517 | 7.5 HIGH | MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of S |
| CVE-2026-81518 | 7.5 HIGH | BI Connector Optional Client Certificate Verification Allows Unauthenticated Connections |
| CVE-2026-81520 | 7.5 HIGH | MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaus |
| CVE-2026-81533 | 7.1 HIGH | MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values |
| CVE-2026-76797 | 6.3 MEDIUM | MongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generate |
| CVE-2026-77184 | 5.2 MEDIUM | MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE O |
| CVE-2026-76794 | 4.6 MEDIUM | MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When Processing Da |
No comments yet