Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the firstname, middlename and lastname parameters in the /php-spms/admin/?page=user endpoint.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Service Provider Management System 跨站脚本漏洞
Vulnerability Description
Service Provider Management System是Carlo Montero个人开发者的一个基于 web 的应用程序。旨在为服务提供商公司提供动态网站。 Service Provider Management System v.1.0版本存在跨站脚本漏洞,该漏洞源于允许远程攻击者通过 /php-spms/admin/?page=user 端点中的firstname、 middlename 、lastname参数执行任意代码或获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A