Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_psw HTTP request body parameter for the acp interface. An admin user can inject malicious client-side script into the affected parameter without any form of input sanitization. The injected payload will be executed in the browser of a user whenever one visits the affected module page.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
flatCore CMS 跨站脚本漏洞
Vulnerability Description
flatCore是一套基于PHP和SQLite的轻量级内容管理系统(CMS)。 flatCore CMS 2.0.0 build 139版本之前存在跨站脚本漏洞,该漏洞源于程序接受了恶意的客户端脚本,而没有进行适当的检测,攻击者可利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A