Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. Due to the rich and highly privileged functionality offered by the Teacher Console, the ability to silently exploit Cross Site Scripting (XSS) on the Teacher Machine enables remote code execution on any connected student machine (and the teacher's machine).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Faronics Insight 跨站脚本漏洞
Vulnerability Description
Faronics Insight是加拿大Faronics公司的一个有效的课堂管理工具。 Faronics Insight 10.0.19045 版本存在安全漏洞,该漏洞源于使用中间人攻击的方式可以在教师端和学生端呈现未经转义的内容,从而在对应客户端上执行JavaScript代码。由于教师端提供的丰富和高度特权的功能,在教师端利用跨站脚本 (XSS) 可以在连接的任意学生端(和教师端)上远程执行代码。
CVSS Information
N/A
Vulnerability Type
N/A