MoguBlog 6.2 及以下版本在 POST 端点未能验证评论作者的身份,导致已认证用户可以将评论归属到任意其他用户名下。攻击者可以在请求体中提供任意 值,从而冒充其他账户(包括管理员)发布评论。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89262 | 7.5 HIGH | MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check |
| CVE-2026-89260 | 7.5 HIGH | MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback |
| CVE-2026-89261 | 6.5 MEDIUM | MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints |
| CVE-2026-89263 | 5.3 MEDIUM | MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint |
| CVE-2026-89265 | 4.3 MEDIUM | MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint |
No comments yet