Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. This can result in account takeover via session token theft.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ClinicCases 跨站脚本漏洞
Vulnerability Description
ClinicCases是一个开源案例管理系统,专为法学院诊所设计。 ClinicCases 7.3.3版本存在跨站脚本漏洞,该漏洞源于软件对于用户提交的参数缺少有效的验证和过滤。漏洞允许低权限攻击者可利用该漏洞引入任意JavaScript来设置帐户参数。XSS有效负载将在任何查看相关内容的用户的浏览器中执行。攻击者可以通过会话令牌窃取来接管帐户。
CVSS Information
N/A
Vulnerability Type
N/A