Yonyou u8是中国用友网络科技(Yonyou)公司的一个企业 ERP 系统。 Yonyou u8 v13.0 版本的 /u8sl/WebHelp 组件存在跨站脚本漏洞,该漏洞源于 /u8sl/WebHelp 中存在一个基于 DOM 的跨站脚本漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Yonyou U8 13.0 contains a DOM-based cross-site scripting vulnerability via the component /u8sl/WebHelp. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26263.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-25582 | ClassCMS 跨站脚本漏洞 | |
| CVE-2022-0897 | Red Hat libvirt 安全漏洞 | |
| CVE-2022-0435 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2021-3933 | ILM OpenEXR 输入验证错误漏洞 | |
| CVE-2021-4203 | Linux kernel 资源管理错误漏洞 | |
| CVE-2021-4147 | Red Hat libvirt 安全漏洞 | |
| CVE-2021-3941 | ILM OpenEXR 数字错误漏洞 | |
| CVE-2022-0330 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2021-43091 | YesWiki SQL注入漏洞 | |
| CVE-2022-25577 | ALF-BanCo 信任管理问题漏洞 | |
| CVE-2022-25574 | DouPHP 跨站脚本漏洞 | |
| CVE-2022-27881 | OpenBSD 安全漏洞 | |
| CVE-2022-27882 | OpenBSD 安全漏洞 | |
| CVE-2021-43636 | TotoLink T10 安全漏洞 | |
| CVE-2021-22100 | cloud foundry 资源管理错误漏洞 | |
| CVE-2021-4157 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2021-4202 | Linux kernel 资源管理错误漏洞 | |
| CVE-2021-20290 | OpenSC 安全漏洞 | |
| CVE-2021-3567 | SUSE OpenStack Cloud 缓冲区错误漏洞 | |
| CVE-2021-3582 | QEMU 缓冲区错误漏洞 |
Showing top 20 of 53 CVEs. View all on vendor page → →
No comments yet