Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/modern.html file for SCORM Engine versions < 20.1.45.914, 21.1.x < 21.1.7.219. The issue exists because there are no limitations on the domain or format of the url supplied by the user, allowing an attacker to craft malicious urls which can trigger a reflected XSS payload in the context of a victim's browser.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Rusici Software SCORM Engine 跨站脚本漏洞
Vulnerability Description
Rusici Software SCORM Engine是美国Rusici Software公司的一个可集成的学习标准平台。为学习应用程序提供通用 API 以正确导入、启动和跟踪标准化的电子学习内容。 Rusici Software SCORM Engine 20.1.45.914之前版本、21.1.x版本至21.1.7.219之前版本存在安全漏洞,该漏洞源于 /defaultui/player/modern.html 文件中的 playerConfUrl 参数中存在反射型跨站点脚本 (XSS) 漏洞。攻
CVSS Information
N/A
Vulnerability Type
N/A