在 light0011 cms(提交哈希 c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930)中发现了一个弱点。该漏洞影响 UEditor 组件中 文件里的 函数。对参数 的操作会导致服务端请求伪造(SSRF)漏洞。攻击者可以从远程发起攻击。该漏洞的利用方式已公开,可被用于攻击。该产品采用滚动发布模式,持续提供更新,因此无法获取受影响或已修复版本的具体版本信息。项目方已通过问题报告提前得知该问题,但尚未作
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85379 | 7.3 HIGH | light0011 cms Query Builder ChapterController.class.php searchChapter sql injection |
| CVE-2026-85381 | 5.3 MEDIUM | light0011 cms Chapter Controller ChapterController.class.php authorization |
| CVE-2026-85382 | 4.3 MEDIUM | light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scr |
No comments yet