infility global是infility个人开发者的一个全球化服务平台。 Infility Global 2.15.20之前版本存在SQL注入漏洞,该漏洞源于在SQL查询中使用前未对import_list()、url_detail()和file_detail()管理页面回调中的orderby和order参数进行清理或验证,可能导致经过身份验证的具有Editor级或更高级别的攻击者执行基于时间盲注的SQL注入攻击,并从数据库中提取敏感数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Infility Global | < 2.15.20 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Infility Global | 0 ~ 2.15.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-8172 | Simple Basic Contact Form <= 20250114 - Reflected XSS | |
| CVE-2026-8163 | Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter | |
| CVE-2026-8378 | Frontend File Manager Plugin <= 23.6 - Subscriber+ Stored Cross-Site Scripting via File Re | |
| CVE-2026-8379 | Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download |
No comments yet