Geeklog-Core / geeklog

Geeklog - The Secure CMS.
https://www.geeklog.net
25 stars 19 forks source link

CVE-2023-37787, CVE-2023-37786, CVE-2023-46058, CVE-2023-46058 #1158

Open hirorongl opened 7 months ago

hirorongl commented 7 months ago

2023-10-23 [CVE-2023-46058] /admin/trackback.phpのXSS https://www.cve.org/CVERecord?id=CVE-2023-46059

2023-10-23 [CVE-2023-46058] /admin/group.phpのXSS https://www.cve.org/CVERecord?id=CVE-2023-46058

2023-07-13 [CVE-2023-37786] /admin/configuration.phpのXSS https://www.cve.org/CVERecord?id=CVE-2023-37786

2023-07-13 [CVE-2023-37787] /admin/router.phpのXSS https://www.cve.org/CVERecord?id=CVE-2023-37787

hirorongl commented 7 months ago

93604031f93833bed1566f63e08db16fbf68f137

hirorongl commented 7 months ago

diff.patch

eSilverStrike commented 7 months ago

@hirorongl Thanks for the patch!

hirorongl commented 6 months ago

This patch does not fix CVE-2023-37786 please don't closed