Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Quali CloudShell before 8 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Name or (2) Description parameter to RM/Reservation/ReserveNew; the (3) Description parameter to RM/Topology/Update; the (4) Name, (5) Description, (6) ExecutionBatches[0].Name, (7) ExecutionBatches[0].Description, or (8) Labels parameter to SnQ/JobTemplate/Edit; or (9) Alias or (10) Description parameter to RM/AbstractTemplate/AddOrUpdateAbstractTemplate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Quali CloudShell 跨站脚本漏洞
Vulnerability Description
Quali CloudShell是以色列Quali System公司的一套用于提供混合云的全堆栈IT环境的云沙箱软件。 Quali CloudShell 8之前的版本中存跨站脚本漏洞。远程攻击者可通过多种方法利用该漏洞注入任意的Web脚本或HTML。(多种方法包括:向RM/Reservation/ReserveNew发送‘Name’或‘Description’参数,向RM/Topology/Update发送‘Description’参数,向SnQ/JobTemplate/Edit发送‘Name’、‘Des
CVSS Information
N/A
Vulnerability Type
N/A