Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Carousel Wiget' section and choosing our carousel widget created above, in 'Photo URL' and 'YouTube URL' plugin.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CSZ CMS 跨站脚本漏洞
Vulnerability Description
CSZ CMS是一套基于PHP的开源内容管理系统(CMS)。 CSZ CMS 1.3.0版本存在安全漏洞,攻击者利用该漏洞可以通过在Carousel Wiget中输入的精心设计的有效负载,并通过在Photo URL和YouTube URL上面创建的轮播小部件来执行任意 Web 脚本或 HTML 。
CVSS Information
N/A
Vulnerability Type
N/A