CNNVD-202601-2970 Information

CNNVD ID

CNNVD-202601-2970

CVE-2026-1105

  • CNNVD Published: 2026-01-18

Description (Chinese)

EasyCMS是EasyCMS社区的一个基于Php的建站系统。 EasyCMS 1.6及之前版本存在SQL注入漏洞,该漏洞源于对文件/UserAction.class.php中参数_order的错误操作,可能导致SQL注入攻击。

Description (English)

EASYCMS is a Php-based station system for the community of EASYCMS. The EasyCMS 1.6 and previous versions contained an injection loophole in SQL, which stemmed from an error in the operation of the parameter order in the document/Useraction.class.php, which could lead to an attack on SQL.

Hazard Level

Medium

Vulnerability Type

SQL注入

Affected Vendor

EasyCMS

Published

2026-01-18

Last Modified

2026-02-24

References

https://github.com/ueh1013/VULN/issues/15 https://vuldb.com/?ctiid.341697 https://vuldb.com/?id.341697 https://vuldb.com/?submit.731465 https://access.redhat.com/security/cve/cve-2026-1105

Share on: