CNNVD-202601-2971 Information
CNNVD ID
CNNVD-202601-2971
Related CVE
- CNNVD Published: 2026-01-18
Description (Chinese)
EyouCMS是中国易优(Eyou)公司的一套基于ThinkPHP的开源内容管理系统(CMS)。 EyouCMS 1.7.1/5.0及之前版本存在代码问题漏洞,该漏洞源于对文件Diyajax.php中组件Member Avatar Handler的函数check_userinfo的参数viewfile的错误操作,可能导致不受限制的上传。
Description (English)
EyouCMS is an open-source content management system (CMS) based on ThinkPHP for Eyou. EyouCMS 1.7.1/5.0 and previous versions have a code problem loophole, which stems from an error in the performance of the function check userinfo parameter viewfile for component Member Avatar Handler in Diyajax.php, which may lead to unrestricted upload.
Hazard Level
High
Vulnerability Type
代码问题
Affected Vendor
易优
Published
2026-01-18
Last Modified
2026-02-24
References
https://github.com/24-2021/vul3/blob/main/Eyoucms/Eyoucms%3D1.7.1%20check_userinfo%20api%20viewfile%20exists%2C%20causing%20code%20execution%20due%20to%20file%20inclusion.md https://github.com/24-2021/vul3/blob/main/Eyoucms/Eyoucms%3D1.7.1%20check_userinfo%20api%20viewfile%20exists%2C%20causing%20code%20execution%20due%20to%20file%20inclusion.md#poc https://vuldb.com/?submit.731540 https://vuldb.com/?ctiid.341699 https://vuldb.com/?id.341699 https://access.redhat.com/security/cve/cve-2026-1107
Share on: