Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Publify - Stored Cross-Site Scripting (XSS) in Editor
Vulnerability Description
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Publify 跨站脚本漏洞
Vulnerability Description
Publify是一个简单但功能齐全的网络发布软件。 Publify v8.0 至 v9.2.4版本存在安全漏洞,攻击者可利用该漏洞在创建页面/文章时插入和执行任意JavaScript代码。
CVSS Information
N/A
Vulnerability Type
N/A