Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that are mishandled during a preview, aka APPSEC-1503.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Magento Community Edition和Enterprise Edition 跨站脚本漏洞
Vulnerability Description
Magento是美国Magento公司的一套开源的PHP电子商务系统,它提供权限管理、搜索引擎和支付网关等功能。Magento Community Edition(CE)是一个社区版。Magento Enterprise Edition(EE)是一个企业版。 Magento CE和EE 2.0.10之前的版本和2.1.2之前的2.1.x版本中存在跨站脚本漏洞。远程攻击者可借助邮件模板利用该漏洞执行恶意的代码。
CVSS Information
N/A
Vulnerability Type
N/A