Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
vFairs 跨站脚本漏洞
Vulnerability Description
vFairs是新加坡vFairs公司的一个虚拟事件平台。可举办精彩的在线会议,贸易展览,招聘会等等。 vFairs 3.3 版本存在安全漏洞,该漏洞允许登录到vFairs虚拟会议的任何用户都可以修改任何其他用户的信息,,这可能导致跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A