Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
dsmall 跨站脚本漏洞
Vulnerability Description
dsmall是一套多用户的平台级网上商城系统。 dsmall 20180320版本中存在跨站脚本漏洞,该漏洞源于在public/index.php/home/memberaddress/edit/address_id/2.html页面,程序没有正确的处理街道地址信息。远程攻击者可通过向public/index.php/home/memberaddress/index.html页面发送特制的街道地址利用该漏洞向页面中注入任意的JavaScript代码或HTML。
CVSS Information
N/A
Vulnerability Type
N/A