Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
gougucms 跨站脚本漏洞
Vulnerability Description
gougucms(勾股CMS)是中国勾股开源开源的一套基于 ThinkPHP6 + Layui + MySql 打造的轻量级的通用后台管理框架。 gougucms v4.08.18版本存在跨站脚本漏洞,该漏洞源于允许攻击者通过 headimgurl 参数注入精心设计的有效负载,执行任意 Web 脚本或 HTML。
CVSS Information
N/A
Vulnerability Type
N/A