MoguBlog 版本 6.2 及以下存在 XML 外部实体(XXE)注入漏洞,位于微信回调处理程序中的 POST /wechat/wechatCheck 接口。 方法将原始请求体直接传递给 ,而该方法内部使用的 dom4j 未经过加固,未对 DTD 声明或外部实体引用进行限制。未经认证的远程攻击者可通过在 XML 中注入包含外部参数实体的 DOCTYPE 声明,从而读取任意本地文件或触发出站 HTTP 请求;已解析的实体内容会在错误响应中反映出来。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89262 | 7.5 HIGH | MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check |
| CVE-2026-89261 | 6.5 MEDIUM | MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints |
| CVE-2026-89263 | 5.3 MEDIUM | MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint |
| CVE-2026-89264 | 4.3 MEDIUM | MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity |
| CVE-2026-89265 | 4.3 MEDIUM | MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint |
No comments yet