Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an attacker to inject code that will later be executed by legitimate users when they open the assets containing the JavaScript code. This would allow an attacker to perform unauthorized actions in the application on behalf of legitimate users or spread malware via the application. By using the “Assets Upload” function, an attacker can abuse the upload function to upload a malicious PDF file containing a stored XSS.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Marmind 跨站脚本漏洞
Vulnerability Description
Marmind是奥地利Marmind公司的一个用于管理协调营销活动的Web平台。该平台将营销预算和组合结果组合到一个营销计划中,供使用者进行分析。 Marmind web application 4.1.141.0版本存在跨站脚本漏洞,该漏洞允许攻击者可以滥用上传功能来上传包含XSS的恶意PDF文件。
CVSS Information
N/A
Vulnerability Type
N/A