Releases15
Frequency1 month 2 weeks
Last Release
Stars399
ZrLog 是一款基于 Java 的开源博客系统。它提供文章、分类、标签、评论、主题、插件、静态化和在线升级等功能,内置 Markdown 编辑器,管理界面基于 React 和 Ant Design 构建。

CVE History

CVEPublishedCVSS v3CVSS v2
9.1 CRITICAL

Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).

6.1 MEDIUM

Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/addComment function.

9.8 CRITICAL7.5 HIGH

A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell

7.8 HIGH6.8 MEDIUM

ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file

6.1 MEDIUM4.3 MEDIUM

Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.

6.1 MEDIUM4.3 MEDIUM

A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.

5.7 MEDIUM3.5 LOW

zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download the database backup file directly.

5.4 MEDIUM3.5 LOW

An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area.

4.3 MEDIUM

An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area.

6.5 MEDIUM

An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter.

4.3 MEDIUM

An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.