Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WeCenter 3.2.0 through 3.2.2 has XSS in the views/default/question/index.tpl.html htmlspecialchars_decode function via the /?/publish/ajax/publish_question/ question_content parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WeCenter ‘htmlspecialchars_decode’函数跨站脚本漏洞
Vulnerability Description
WeCenter是一套开源的社区问答程序。该程序包括内容整理、内容分类和内容检索等功能。 WeCenter 3.2.0至3.2.2版本中的views/default/question/index.tpl.html文件的‘htmlspecialchars_decode’函数存在跨站脚本漏洞。远程攻击者可借助‘question_content’参数利用该漏洞注入任意Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A