ଜମା କରନ୍ତୁ #187650: Dedebiz v6.2.10 exists XSS injectionସୂଚନା

ଶୀର୍ଷକDedebiz v6.2.10 exists XSS injection
ବର୍ଣ୍ଣନାDedebiz v6.2.10 has a stored XSS injection vulnerability. Conditions of use: 1. The administrator has enabled the members feature (this is a basic feature that needs to be enabled) 2. Register as a member and pass the email verification This user can first publish an article containing normal information and then modify the article in the document management. By editing articles in source mode, special payloads can be used to bypass the system's xss filter, allowing malicious code injection and the introduction of a malicious js file from a remote host. After the administrator previews the article or approves the article, the malicious code will be automatically executed in the browser.
ଉତ୍ସ⚠️ https://github.com/Wkingxc/CVE/blob/master/dedebiz_XSS.pdf
ଉପଭୋକ୍ତା
 funnn7 (UID 50471)
ଦାଖଲ07/27/2023 06:31 AM (3 ବର୍ଷ ବର୍ଷ ago)
ମଧ୍ୟମ ଧରଣର08/04/2023 11:11 PM (9 days later)
ସ୍ଥିତିଗ୍ରହଣ କରାଯାଇଛି
VulDB ଏଣ୍ଟ୍ରି236186 [DedeBIZ 6.2.10 Article କ୍ରସ୍ ସାଇଟ୍ ସ୍କ୍ରିପ୍ଟିଂ]
ପଏଣ୍ଟ20

Want to stay up to date on a daily basis?

Enable the mail alert feature now!