Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Elcomplus SmartPtt Cross-site Scripting
Vulnerability Description
Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Elcomplus SmartPPT 跨站脚本漏洞
Vulnerability Description
Elcomplus SmartPPT是美国Elcomplus公司的一个集成语音和数据调度软件。 SmartPPT SCADA Server v1.4 版本存在跨站脚本漏洞,经过身份验证的攻击者可以将任意 JavaScript 注入关键参数。
CVSS Information
N/A
Vulnerability Type
N/A