Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the group comments text field.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JEESNS 跨站脚本漏洞
Vulnerability Description
福州凌夕网络科技 JEESNS是中国福州凌夕网络科技公司的一款基于JAVA企业级平台研发的社交管理系统。依托企业级JAVA的高效、安全、稳定等优势,开创国内JAVA版开源SNS先河。数据库使用MYSQL,全部源代码开放。 Jeesns 1.4.2 的 /group/comment 组件中存在安全漏洞,该漏洞允许攻击者通过组评论文本字段中精心设计的有效负载执行任意 Web 脚本或 HTML。
CVSS Information
N/A
Vulnerability Type
N/A