Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/exp.svg" that will point to http://localhost/pagekit/storage/exp.svg. When a user comes along to click that link, it will trigger a XSS attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pagekit 跨站脚本漏洞
Vulnerability Description
Pagekit是一套模块化的、轻量级CMS(内容管理系统)。 PageKit v1.0.18 存在跨站脚本漏洞,该漏洞源于SVG文件可能包含恶意脚本,触发XSS攻击。
CVSS Information
N/A
Vulnerability Type
N/A