Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
UliCMS 2023.1 Stored Cross-Site Scripting via SVG File Upload
Vulnerability Description
UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the file management interface that execute arbitrary scripts when viewed by other users.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
UliCMS 跨站脚本漏洞
Vulnerability Description
UliCMS是UliCMS开源的一个内容管理系统(CMS)。该系统支持访问控制和所见即所得编辑等功能。 UliCMS 2023.1版本存在跨站脚本漏洞,该漏洞源于攻击者可上传嵌入JavaScript的恶意SVG文件,可能导致存储型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A