Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/poc.svg" that will point to http://localhost/pagekit/storage/poc.svg. When a user comes along to click that link, it will trigger a XSS attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
YOOtheme Pagekit 跨站脚本漏洞
Vulnerability Description
YOOtheme Pagekit是德国YOOtheme公司的一套构建在Symfony基础上的模块化、轻量级内容管理系统(CMS)。该系统提供博客、用户权限管理和多媒体管理等功能。 YOOtheme Pagekit 1.0.13及之前版本中存在跨站脚本漏洞。远程攻击者可借助图片上传功能利用该漏洞上传恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A