Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java could be bypassed, as demonstrated by a <svg/onLoad=confirm substring. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-12429.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JEESNS 安全漏洞
Vulnerability Description
JEESNS是一款基于Java和MySQL的企业级开源社交管理系统搭建平台。该平台包括微博模块、群组模块和文章模块等。 JEESNS 1.3版本中的com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java文件存在安全漏洞。远程攻击者可利用该漏洞绕过过滤器,执行恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A