MoguBlog 在 6.2 版本中,其评论删除接口存在一个授权绕过漏洞。该接口在执行所有权校验时,依据的是请求体(request-body)中的字段,而非当前经过身份验证的用户(authenticated principal)的身份。攻击者可以通过从无需认证的列表接口中获取到的评论 UID 和作者 UID,来删除任意评论及其回复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89260 | 7.5 HIGH | MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback |
| CVE-2026-89261 | 6.5 MEDIUM | MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints |
| CVE-2026-89263 | 5.3 MEDIUM | MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint |
| CVE-2026-89264 | 4.3 MEDIUM | MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity |
| CVE-2026-89265 | 4.3 MEDIUM | MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint |
No comments yet