Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Fulusso v1.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in /BindAccount/SuccessTips.js. This vulnerability allows attackers to inject malicious code into a victim user's device via open redirection.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Fulusso 跨站脚本漏洞
Vulnerability Description
Fulusso是一个基于 React + Asp.net Core开发的单点登录系统。 Fulusso v1.1版本存在安全漏洞,该漏洞源于/BindAccount/SuccessTips.js中包含基于DOM的跨站点脚本(XSS)漏洞。攻击者可利用该漏洞通过开放重定向向受害用户的设备注入恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A