天下漏洞,尽知其名
MEDIUM

CVE-2026-101018 XunruiCMS SQL注入漏洞

影响攻击者可远程注入SQL,窃取或篡改数据库数据

AI 研判

XunruiCMS(迅睿CMS)是一款由dayrui开发的内容管理系统。其后台会员模块的组编辑功能存在SQL注入漏洞,影响版本至4.7.2。该漏洞的利用细节已被公开披露,厂商未作回应。

影响范围

XunruiCMS

dayrui XunruiCMS 4.7.2及之前版本,具体受影响范围以官方公告为准,暂无公开信息。

漏洞详情

漏洞位于dayrui/App/Member/Controllers/Admin/Home.php文件的group_all_edit函数中,程序未对groupid参数做充分过滤即拼接进SQL语句,导致注入。攻击者可构造恶意groupid参数远程触发,从而执行任意SQL查询。该漏洞利用方式已公开。

利用条件与风险

攻击需能访问后台组编辑相关接口,通常需具备一定权限或结合其他手段绕过认证;由于PoC已公开,实战中被扫描利用的风险较高。

修复建议

厂商未作回应,暂无官方补丁信息。建议对groupid参数进行严格类型校验与参数化查询,限制后台接口访问权限,并部署WAF拦截注入特征。

原始情报

A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the file dayrui/App/Member/Controllers/Admin/Home.php of the component Group Editing. This manipulation of the argument groupid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.