在 SeaCMS 13.6 及更低版本中检测到一个安全漏洞。该漏洞影响组件“Locoy Collector”中文件 seacms_locoy_news.php 的 parseIf 函数。攻击者可通过操纵参数 pwd 实现代码注入。该漏洞可被远程触发。该漏洞的利用方式已公开披露,并可能被实际利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | SeaCMS | 13.0 |
cpe:2.3:a:seacms:seacms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85138 | 7.3 HIGH | SeaCMS WeChat index.php addslashes sql injection |
| CVE-2026-85135 | 6.3 MEDIUM | ILIAS MediaPool ZipAdapter.php uploadMultipleSubtitleFileObject unrestricted upload |
No comments yet