Craft CMS是Craft CMS公司的一套内容管理系统(CMS)。 Craft CMS 5.10.12之前版本存在代码注入漏洞,该漏洞源于element-index端点对criteria参数处理不当,允许已认证的内容编辑器实例化任意类,攻击者可通过criteria[withTransforms][0][class]注入恶意类,并利用PHP gadget链使itemFile指向包含User-Agent请求日志中的恶意负载,从而执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86730 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE |
| CVE-2026-86731 | 6.5 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController |
No comments yet