Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
eZ Publish search模块跨站脚本漏洞
Vulnerability Description
eZ Publish是挪威eZ Systems公司的一套开源的PHP内容管理系统和开发框架(CMS/CMF)。该系统提供可自由定制和可扩展的内容模型,适用于新闻发布、电子商务(B2B与B2C)、门户与社区网站。search module是其中的一个搜索模块。 eZ Publish 5.4.0版本至5.4.9版本和5.3.12及之前的版本中的search模块存在跨站脚本漏洞。远程攻击者可利用该漏洞注入脚本,可能窃取身份验证证书。
CVSS Information
N/A
Vulnerability Type
N/A