在 kequnlong shiyi-blog 1.2.1 及之前版本中发现一个安全漏洞。受影响的组件是 中位于 文件中的 函数。通过对 / 参数的操纵,可引发跨站脚本(XSS)攻击。该攻击可远程发起。项目方已通过问题报告较早地获知了该问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| quequnlong | shiyi-blog | 1.2.0 |
cpe:2.3:a:quequnlong:shiyi-blog:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90527 | 4.3 MEDIUM | quequnlong shiyi-blog Add Message API index.vue cross site scripting |
| CVE-2026-90564 | 3.5 LOW | quequnlong shiyi-blog chat sendMsg Endpoint index.vue SysChatMsgMapper.getChatMsgList cros |
No comments yet