Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
xTuple PostBooks 安全漏洞
Vulnerability Description
xTuple PostBooks是一套只在云端或本地服务器中运行的全功能的业务管理系统。该系统包括销售管理、采购管理以及库存和分销管理等功能。 xTuple PostBooks 4.7.0版本中的guiclient/guiclient.cpp文件存在安全漏洞,该漏洞源于程序在启动程序之前,没有验证字符串。远程攻击者可借助特制的URL利用该漏洞实施参数注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A