漏洞关键信息 Title: moxi159753 mogu_blog_v2 <=v5.2 Unrestricted Upload of File with Dangerous Type Description: - Mogu_blog_v2, a microservice-based blog system, contains an unauthenticated arbitrary file upload vulnerability. - The system allows unauthenticated access to , and the controller method does not verify authentication. - Attackers can upload harmful files including HTML, JavaScript, CSS, SQL, Java, and Vue files, leading to stored XSS attacks, phishing, malware distribution, and website defacement. Source: - GitHub Link User: sh7err04 (UID 92493) Submission: 11/10/2025 02:33 PM Moderation: 11/30/2025 08:51 PM Status: Accepted VulDB entry: 333824 Points: 20