Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows XSS in the login page via the loginmessage parameter, the text editor via the src attribute of HTML elements, the translations menu via the foldername parameter, the author page via the link URL, or the upload image functionality via an SVG document containing JavaScript.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bloomreach Experience Manager 跨站脚本漏洞
Vulnerability Description
Bloomreach Experience Manager是美国Bloomreach公司的一个应用软件。提供AI驱动的搜索和推销工具。 Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2 存在跨站脚本漏洞,该漏洞源于loginmessage参数允许登录页面中的XSS。
CVSS Information
N/A
Vulnerability Type
N/A