Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CIPPlanner CIPAce 注入漏洞
Vulnerability Description
CIPPlanner CIPAce是美国CIPPlanner公司的一套业务流程自动化和应用程序开发平台。 CIPPlanner CIPAce 9.1版本(Build 2019092801)中存在注入漏洞。攻击者可通过发送带有HTML数据的HTTP POST请求利用该漏洞以用户信任的电子邮件地址发送电子邮件。
CVSS Information
N/A
Vulnerability Type
N/A