在 liufee FeehiCMS 2.1.1 及更早版本中发现了一个安全弱点。该弱点影响了组件“Cookie 校验”(Cookie Validation)中文件 的一个未知功能。对该文件中参数 的操纵会导致使用硬编码的加密密钥。该攻击可以远程实施。利用代码(exploit)已公开,可能被用于实际攻击。项目方早已通过问题报告被通知了此问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86239 | 5.3 MEDIUM | liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload |
| CVE-2026-86240 | 4.7 MEDIUM | liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery |
No comments yet