Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JEESNS 跨站脚本漏洞
Vulnerability Description
JEESNS是一款基于Java和MySQL的企业级开源社交管理系统搭建平台。该平台包括微博模块、群组模块和文章模块等。 JEESNS 1.3版本中的com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java文件存在跨站脚本漏洞。远程攻击者可借助HTML EMBED元素利用该漏洞注入任意的Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A