在 WuzhiCMS 4.1.0 及更早版本中发现了一个漏洞。该漏洞影响组件 Login 中文件 的某个未知功能。通过操纵参数 ,攻击者可引发开放重定向(Open Redirect)问题。该攻击可远程发起。相关的利用方法(exploit)已公开,并可能被用于实际攻击。目前系统仅使用 进行过滤,该函数是一个专门用于清除 XSS 关键字/实体的清理器。供应商在漏洞披露初期已被联系,但未以任何方式作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | WuzhiCMS | 4.0 |
cpe:2.3:a:wuzhicms:wuzhicms:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94110 | 7.3 HIGH | QCMS Content Detail Controllers.php self_Tmp sql injection |
| CVE-2026-94103 | 4.7 MEDIUM | RooCMS Frontend Rendering site_pagePHP.php eval code injection |
No comments yet