Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4j85-4728-jr5q

Опубликовано: 11 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 6.5

Описание

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.

EPSS

Процентиль: 39%
0.00456
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 6.5
nvd
12 дней назад

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.

EPSS

Процентиль: 39%
0.00456
Низкий

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-306