erxes是erxes开源的一个开源 Hubspot/Qualtrics 替代方案。使 SaaS 提供商和数字营销机构/开发商能够为其整个业务创造独特的体验。 erxes 0.22.3及之前版本存在安全漏洞,该漏洞源于存在跨站脚本漏洞,攻击者利用该漏洞可以导致客户端代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Erxes before 0.23.0 contains a cross-site scripting vulnerability. The value of topicID parameter is not escaped and is triggered in the enclosing script tag. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-32853.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-32850 | 6.1 MEDIUM | jQuery MiniColors vulnerable to Cross-site Scripting |
| CVE-2021-32851 | 6.1 MEDIUM | jQuery MiniColors vulnerable to Cross-site Scripting |
| CVE-2021-32854 | 6.1 MEDIUM | textAngular text editor vulnerable to Cross-site Scripting |
| CVE-2021-32855 | 6.1 MEDIUM | vditor vulnerable to Cross-site Scripting |
| CVE-2021-32860 | 6.1 MEDIUM | iziModal vulnerable to Cross-site Scripting |
No comments yet