Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration parameter "unique_error_numbers" is not set, remote attackers can inject arbitrary web script or HTML via 'action, cargo, panel' parameters that can lead to data leakage.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
AudimexEE 跨站脚本漏洞
Vulnerability Description
Audimex AG AudimexEE是德国Audimex AG的一个用于审核管理的系统。该系统可围绕公司业务满足复杂的审核流程,支持根据用于量身定制并且部署独立于平台。 AudimexEE 14.1.1之前版本存在跨站脚本漏洞,如果unique_error_numbers安全参数没有被设置,远程攻击者可通过action, cargo, panel进行web脚本或者html注入,从而导致数据泄露。
CVSS Information
N/A
Vulnerability Type
N/A