Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload will be triggered every time a user browses the reports page.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zucchetti InfoBusiness 跨站脚本漏洞
Vulnerability Description
Zucchetti InfoBusiness是意大利Zucchetti公司的一套商业智能解决方案。该产品支持绩效分析和数据统计等功能。 Zucchetti InfoBusiness 4.4.1及之前版本中存在安全漏洞,该漏洞源于InfoBusiness Web组件没有正确验证Title字段。攻击者可利用该漏洞注入客户端脚本。
CVSS Information
N/A
Vulnerability Type
N/A