以下是该漏洞描述的中文翻译: MoguBlog 6.2 及更早版本 未能对 接口的请求进行身份验证,使得未认证的远程攻击者能够禁用任意用户的邮件通知功能。远程调用者可以在 Redis 缓存中修改任意用户标识符的 标志位,从而在未经授权的情况下抑制回复通知。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89262 | 7.5 HIGH | MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check |
| CVE-2026-89260 | 7.5 HIGH | MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback |
| CVE-2026-89261 | 6.5 MEDIUM | MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints |
| CVE-2026-89264 | 4.3 MEDIUM | MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity |
| CVE-2026-89265 | 4.3 MEDIUM | MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint |
No comments yet