在 liufee FeehiCMS 2.1.1 及之前版本中发现了一个漏洞。受影响的组件是 UEditor Widget,具体为文件 中的 函数。该操纵会导致不受限制的上传漏洞,且可被远程利用。该漏洞的利用代码已公开,可能被实际使用。项目方已通过问题报告提前获知此问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86240 | 4.7 MEDIUM | liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery |
| CVE-2026-86241 | 4.3 MEDIUM | liufee FeehiCMS Cookie Validation main-local.php hard-coded key |
No comments yet