Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) multi_title parameter to blocks/add/; (2) cost, (3) days, or (4) title[en] parameter to plans/add/; (5) name or (6) title[en] parameter to fields/group/add/ in admin/manage/; or (7) f[accounts][fullname] or (8) f[accounts][username] parameter to advsearch/. NOTE: This might overlap CVE-2011-5211. NOTE: it was later reported that the f[accounts][fullname] and f[accounts][username] vectors might also affect 2.2.2.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Subrion CMS 多个跨站脚本漏洞
Vulnerability Description
Subrion CMS中存在多个跨站脚本漏洞,这些漏洞源于没有正确的验证用户提供的数据。攻击者提供的HTML和脚本代码可在受影响浏览器上下文中运行,可窃取基于cookie的认证证书或控制站点传达给用户的方式,也可能存在其他攻击。Subrion CMS 2.2.1版本中存在漏洞,其他版本也可能受到影响。
CVSS Information
N/A
Vulnerability Type
N/A