在 liketrek TREK 3.0.22 及更早版本中发现了一个漏洞。受影响的元素是组件“行程条目更新”(Journey Entry Update)中文件 的函数 。该漏洞可导致 SQL 注入攻击。攻击者可以远程发起攻击。升级至 3.1.0 版本即可修复此问题。建议尽快升级受影响的组件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78863 | 6.3 MEDIUM | liketrek TREK Pre-2FA mfa_token authService.ts loginUser improper authentication |
| CVE-2026-78885 | 5.6 MEDIUM | liketrek TREK OIDC Service oidcService.ts findOrCreateUser improper authentication |
| CVE-2026-78886 | 3.7 LOW | liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal |
| CVE-2026-78887 | 3.7 LOW | liketrek TREK Journey Photo Proxy validateShareTokenForAsset authorization |
No comments yet