以下是对该漏洞描述的中文翻译: MoguBlog 6.2 版本及更早版本中,mogu_search 服务中的 Elasticsearch 索引管理端点未做身份验证,暴露给了外部。远程攻击者可以利用这一点,对博客搜索索引执行删除、重建或修改操作。攻击者可以调用 POST 端点来清空整个搜索索引、删除特定文档,或注入恶意的索引条目,从而导致搜索功能返回错误结果或无结果。 --- 翻译说明与优化建议: 1. 专业术语处理: "exposes ... without authentication" 译为“暴露...且未做身
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89262 | 7.5 HIGH | MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check |
| CVE-2026-89260 | 7.5 HIGH | MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback |
| CVE-2026-89263 | 5.3 MEDIUM | MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint |
| CVE-2026-89264 | 4.3 MEDIUM | MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity |
| CVE-2026-89265 | 4.3 MEDIUM | MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint |
No comments yet