GruppoSCAI RealGimm是SCAI公司的一个大型财产和房地产资产的管理解决方案。 GruppoSCAI RealGimm 1.1.37p38版本存在安全漏洞,该漏洞源于存在多个反射型跨站脚本(XSS)漏洞,允许攻击者通过注入精心设计的有效载荷在浏览器上下文中执行任意Javascript。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload injected into the VIEWSTATE parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-41642.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-20900 | 7.1 HIGH | VMware Tools 安全漏洞 |
| CVE-2023-41640 | GruppoSCAI RealGimm SQL注入漏洞 | |
| CVE-2023-41638 | GruppoSCAI RealGimm 代码问题漏洞 | |
| CVE-2023-41637 | GruppoSCAI RealGimm 代码问题漏洞 | |
| CVE-2023-41636 | GruppoSCAI RealGimm SQL注入漏洞 | |
| CVE-2023-41635 | GruppoSCAI RealGimm 安全漏洞 | |
| CVE-2023-41717 | Zscaler Proxy 安全漏洞 | |
| CVE-2023-39912 | ZOHO ManageEngine ADManager Plus 路径遍历漏洞 |
No comments yet