Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smile_code parameter of the component /editprofile.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ImpressCMS 跨站脚本漏洞
Vulnerability Description
ImpressCMS是一套基于MySQL的、模块化的内容管理系统(CMS)。该系统包括新闻发布、论坛和相册等模块。 ImpressCMS v1.4.5及之前版本存在安全漏洞,攻击者利用该漏洞可以通过组件 editprofile.php 中的 smile_code 参数,使用精心设计的有效负载来执行任意 Web 脚本或 HTML。
CVSS Information
N/A
Vulnerability Type
N/A