在 light0011 cms(版本标识:c774dce31c6df0055568a8d5c53d964d99be199d / f72cf46f601efb2a0618c3814cc2f61380b38930)中发现了一个安全漏洞。 该问题影响 文件中的 函数。通过相关操作可触发不受限定的文件上传漏洞。攻击者可通过远程方式发起攻击。 该漏洞的利用代码(exploit)已公开,可被用于实际攻击。 由于该产品采用滚动发布(rolling release)策略以支持持续交付,因此无法明确指定受影响或已修复的具体版本号。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86306 | 7.3 HIGH | light0011 cms Cookie Helper UserModel.class.php improper authentication |
| CVE-2026-86308 | 5.3 MEDIUM | light0011 cms Debug Mode config.php information disclosure |
| CVE-2026-86307 | 4.3 MEDIUM | light0011 cms cross-site request forgery |
No comments yet