Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Pydio version 8.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in ./core/vendor/meenie/javascript-packer/example-inline.php line 48; ./core/vendor/dapphp/securimage/examples/test.mysql.static.php lines: 114,118 that can result in an unauthenticated remote attacker manipulating the web client via XSS code injection. This attack appear to be exploitable via the victim openning a specially crafted URL. This vulnerability appears to have been fixed in version 8.2.1.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pydio 跨站脚本漏洞
Vulnerability Description
Pydio(前称AjaXplorer)是一款基于Web的远程文件管理器。该管理器支持上传和下载文件、在线文件编辑、图片预览等。 Pydio 8.2.0及之前版本中./core/vendor/meenie/javascript-packer/example-inline.php文件的第48行和./core/vendor/dapphp/securimage/examples/test.mysql.static.php文件的第114和118行存在跨站脚本漏洞。远程攻击者可借助特制的URL利用该漏洞操纵web客户
CVSS Information
N/A
Vulnerability Type
N/A