Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gravitee API Management 跨站脚本漏洞
Vulnerability Description
Gravitee API Management是开源Gravitee API管理工具。 Gravitee API Management 1.25.3 之前版本存在安全漏洞,该漏洞源于HTML 注入与电子邮件服务中的路径遍历相结合,允许匿名用户通过 /management/users/register 请求读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A