Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in mvnForum 1.1 GA allows remote authenticated users to inject arbitrary web script or HTML via the topic field, which is later displayed by user/viewthread.jsp through use of the "quick reply button."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
mvnForum Quick Reply Feature 跨站脚本注入漏洞
Vulnerability Description
mvnForum 1.1 GA存在跨站脚本攻击漏洞。远程认证用户可以借助topic字段,注入任意的web脚本或HTML。通过使用"快速回放按钮",user/viewthread.jsp可以显示该topic字段。
CVSS Information
N/A
Vulnerability Type
N/A