在 light0011 CMS(版本标识:c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930)中发现了一个安全缺陷。该缺陷影响 Query Builder 组件中文件 App/Home/Controller/ChapterController.class.php 里的函数 ChapterModel::searchChapter。通过操纵参数 content 可以导致 SQL 注入漏洞。攻击者可远程发动攻击
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85380 | 7.3 HIGH | light0011 cms UEditor controller.php catchimage server-side request forgery |
| CVE-2026-85381 | 5.3 MEDIUM | light0011 cms Chapter Controller ChapterController.class.php authorization |
| CVE-2026-85382 | 4.3 MEDIUM | light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scr |
No comments yet