CNNVD-202601-2971 Information

CNNVD ID

CNNVD-202601-2971

CVE-2026-1107

  • CNNVD Published: 2026-01-18

Description (Chinese)

EyouCMS是中国易优(Eyou)公司的一套基于ThinkPHP的开源内容管理系统(CMS)。 EyouCMS 1.7.1/5.0及之前版本存在代码问题漏洞,该漏洞源于对文件Diyajax.php中组件Member Avatar Handler的函数check_userinfo的参数viewfile的错误操作,可能导致不受限制的上传。

Description (English)

EyouCMS is an open-source content management system (CMS) based on ThinkPHP for Eyou. EyouCMS 1.7.1/5.0 and previous versions have a code problem loophole, which stems from an error in the performance of the function check userinfo parameter viewfile for component Member Avatar Handler in Diyajax.php, which may lead to unrestricted upload.

Hazard Level

High

Vulnerability Type

代码问题

Affected Vendor

易优

Published

2026-01-18

Last Modified

2026-02-24

References

https://github.com/24-2021/vul3/blob/main/Eyoucms/Eyoucms%3D1.7.1%20check_userinfo%20api%20viewfile%20exists%2C%20causing%20code%20execution%20due%20to%20file%20inclusion.md https://github.com/24-2021/vul3/blob/main/Eyoucms/Eyoucms%3D1.7.1%20check_userinfo%20api%20viewfile%20exists%2C%20causing%20code%20execution%20due%20to%20file%20inclusion.md#poc https://vuldb.com/?submit.731540 https://vuldb.com/?ctiid.341699 https://vuldb.com/?id.341699 https://access.redhat.com/security/cve/cve-2026-1107

Share on: