Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
AVE DOMINAplus 1.10.x Cross-Site Request Forgery and XSS Vulnerabilities
Vulnerability Description
AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to exploit login.php parameters and execute arbitrary scripts in user browser sessions.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
AVE DOMINAplus 安全漏洞
Vulnerability Description
AVE DOMINAplus是意大利AVE公司的一个应用系统。用于下一代房屋的最佳家庭自动化系统。 AVE DOMINAplus 1.10.x版本存在安全漏洞,该漏洞源于容易受到跨站请求伪造和跨站脚本攻击,可能导致执行管理操作和任意脚本。
CVSS Information
N/A
Vulnerability Type
N/A