Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people/add` endpoint and nickName, description, lastName, middleName and firstName parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MonicaHQ 跨站脚本漏洞
Vulnerability Description
MonicaHQ是MonicaHQ公司的一个人际关系管理系统。 MonicaHQ 4.0.0 版本存在安全漏洞,远程攻击者攻击者利用该漏洞可以通过 people/add 端点和nickName、description、lastName、middleName 和 firstName 参数中的 CSTI在应用程序中执行恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A