Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A persistent cross-site scripting (XSS) vulnerability in NexusPHP before 1.7.33 allows remote authenticated attackers to permanently inject arbitrary web script or HTML via the title parameter used in /subtitles.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NexusPHP 跨站脚本漏洞
Vulnerability Description
NexusPHP是一款免费开源的完整的 PT 建站解决方案。 1.7.33 之前的 NexusPHP存在安全漏洞,攻击者可利用该漏洞允许经过身份验证的远程攻击者通过 /subtitles.php 中使用的标题参数永久注入任意 Web 脚本或 HTML。
CVSS Information
N/A
Vulnerability Type
N/A