MoguBlog 6.2 及更早版本存在一个授权绕过漏洞。在 POST /pictureSort/getPictureSortByUid 端点中,缺少用于强制实施基于角色的权限控制的 注解。因此,即使是没有图像分类权限的已认证后台用户,也可以通过提供分类 uid 来获取受限的图像分类记录,包括名称、封面文件 uid、排序顺序和时间戳等元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89262 | 7.5 HIGH | MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check |
| CVE-2026-89260 | 7.5 HIGH | MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback |
| CVE-2026-89261 | 6.5 MEDIUM | MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints |
| CVE-2026-89263 | 5.3 MEDIUM | MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint |
| CVE-2026-89264 | 4.3 MEDIUM | MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity |
No comments yet