在 light0011 CMS(提交哈希 c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930)中发现了一个弱点。该问题影响组件“Cookie Helper”中文件 的未知部分。通过对参数 进行操纵,可导致身份验证不当。攻击者可远程发起攻击。该漏洞的利用方式已公开,可被用于实际攻击。 该产品采用滚动发布系统进行持续交付,因此未披露受影响版本或修复版本的版本信息。项目方早已通过问题报告获悉该问题,但截至目前尚
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86305 | 7.3 HIGH | light0011 cms Upload.class.php upload unrestricted upload |
| CVE-2026-86308 | 5.3 MEDIUM | light0011 cms Debug Mode config.php information disclosure |
| CVE-2026-86307 | 4.3 MEDIUM | light0011 cms cross-site request forgery |
No comments yet