Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Huihuo

#38689of 56,331
7.5Total CVSS
Vulnerabilities · 1
PT-2026-85331
7.5
2026-09-04
Unknown · Light0011 Cms · CVE-2026-85380
**Name of the Vulnerable Software and Affected Versions** light0011 cms (affected versions not specified) **Description** A weakness in the UEditor component allows for server-side request forgery, a technique where an attacker induces the server to make requests to an unintended location. The issue exists within the `catchimage()` function located in the `Public/ueditor/php/controller.php` file. A remote attacker can trigger this by manipulating the `source[]` variable. **Recommendations** As a temporary workaround, consider restricting access to the `catchimage()` function in the `Public/ueditor/php/controller.php` file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.