Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
flatCore-CMS 跨站脚本漏洞
Vulnerability Description
flatCore-CMS是一套基于PHP5和SQLite3的Web内容管理系统(CMS)。 flatCore-CMS 1.4.6版本中的管理日志面板存在跨站脚本漏洞。远程攻击者可借助畸形的用户代理字符串利用该漏洞注入任意的Web脚本后HTML。
CVSS Information
N/A
Vulnerability Type
N/A