Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the "pi-develop/www/script/editor/markitup/preview/markdown.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
pi-engine/pi 跨站脚本漏洞
Vulnerability Description
pi-engine是一套使用PHP和MySQL开发的框架。pi是其中的一个云就绪SaaS平台的多租户应用程序开发引擎。 pi-engine/pi 2.5.0版本中存在跨站脚本漏洞,该漏洞源于pi-develop/www/script/editor/markitup/preview/markdown.php文件没有充分过滤用户提供的输入。远程攻击者可利用该漏洞注入任意Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A