漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS Authentication
Vulnerability Description
Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary JavaScript. The application also exposes database credentials in responses and lacks brute-force protection on authentication endpoints.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Exponent CMS 跨站脚本漏洞
Vulnerability Description
Exponent CMS是Exponent公司的一个提供页面管理与模块化内容编辑能力的网站内容管理系统。 Exponent CMS 2.6版本存在跨站脚本漏洞,该漏洞源于文本编辑端点中的标题和文本块参数存在存储型跨站脚本漏洞,允许认证攻击者注入恶意脚本,攻击者可以注入带有嵌入式SVG onload事件的iframe有效载荷执行任意JavaScript,同时应用程序在响应中暴露数据库凭据,且认证端点缺乏暴力破解保护。
CVSS Information
N/A
Vulnerability Type
N/A