Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 04 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function catchimage of the file Public/ueditor/php/controller.php of the component UEditor. This manipulation of the argument source[] causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | light0011 cms UEditor controller.php catchimage server-side request forgery | |
| First Time appeared |
Light0011
Light0011 cms |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:light0011:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Light0011
Light0011 cms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-04T00:30:09.782Z
Reserved: 2026-09-03T17:53:49.081Z
Link: CVE-2026-85380
No data.
Status : Received
Published: 2026-09-04T01:17:22.710
Modified: 2026-09-04T01:17:22.710
Link: CVE-2026-85380
No data.
OpenCVE Enrichment
Updated: 2026-09-04T03:00:09Z