Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zurmo 跨站脚本漏洞
Vulnerability Description
Zurmo是美国Zurmo公司的一套开源的基于PHP的客户关系管理系统(CRM)。 Zurmo 3.2.1.57987acc3018版本中存在跨站脚本漏洞。远程攻击者可通过向app/index.php/meetings/default/createMeeting发送带有data: URL的‘redirectUrl’参数利用该漏洞在用户浏览器中执行恶意的JavaScript代码。
CVSS Information
N/A
Vulnerability Type
N/A