Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/execute' via the 'SBI_HOST' parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Knowage 跨站脚本漏洞
Vulnerability Description
Knowage是意大利Knowage公司的一套用于在传统资源和大数据系统上进行现代业务分析的开源套件。 Knowage Suite 7.4之前版本存在跨站脚本漏洞。攻击者可利用该漏洞通过SBI_HOST参数在/knowagecockpitengine/api/1.0/pages/execute中注入任意外部脚本。
CVSS Information
N/A
Vulnerability Type
N/A