squidex是一款 Headless CMS 和内容管理中心。 squidex 7.4.0之前版本存在安全漏洞。攻击者利用该漏洞执行跨站脚本攻击。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | It was discovered two reflected cross site scripting (XSS) vulnerabilities in the Squidex open source headless CMS software. The Reflected Cross Site Scripting vulnerabilities affect all versions of Squidex prior to 7.4.0 and affect both authenticated and unauthenticated victim users. | https://github.com/NeCr00/CVE-2023-24278_XSS-in-Squidex | POC详情 |
| 2 | It was discovered two reflected cross site scripting (XSS) vulnerabilities in the Squidex open source headless CMS software. The Reflected Cross Site Scripting vulnerabilities affect all versions of Squidex prior to 7.4.0 and affect both authenticated and unauthenticated victim users. | https://github.com/NeCr00/CVE-2023-24278 | POC详情 |
| 3 | Squidex before 7.4.0 contains a cross-site scripting vulnerability via the squid.svg endpoint. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-24278.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2023-26113 | 7.5 HIGH | Collection 安全漏洞 |
| CVE-2023-1495 | 6.3 MEDIUM | Rebuild SQL注入漏洞 |
| CVE-2023-1494 | 6.3 MEDIUM | IBOS SQL注入漏洞 |
| CVE-2023-1482 | 4.7 MEDIUM | HkCms 代码注入漏洞 |
| CVE-2021-46877 | FasterXML jackson-databind 安全漏洞 | |
| CVE-2023-28606 | MISP 跨站脚本漏洞 | |
| CVE-2023-28607 | MISP 跨站脚本漏洞 | |
| CVE-2023-28609 | Red Hat Ansible 授权问题漏洞 |
暂无评论