Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MonicaHQ 跨站脚本漏洞
Vulnerability Description
MonicaHQ是MonicaHQ公司的一个人际关系管理系统。 MonicaHQ 4.0.0 版本存在安全漏洞,远程攻击者攻击者利用该漏洞可以通过 people:id/relationships 端点和first_name 和 last_name 参数中的 CSTI在应用程序中执行恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A