TOTVS Fluig是葡萄牙TOTVS公司的一个应用软件。用于自动处理ERP任务。 TOTVS Fluig Platform存在跨站脚本漏洞,该漏洞源于文件/mobileredir/openApp.jsp的参数redirectUrl/user会导致跨站脚本漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TOTVS | Fluig Platform | 1.6.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Reflected Cross-Site Scripting in TOTVS Fluig Plataform 1.6.X - 1.8.1 | https://github.com/erickfernandox/CVE-2023-6275 | POC Details |
| 2 | A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /mobileredir/openApp.jsp of the component mobileredir. The manipulation of the argument redirectUrl/user with the input "><script>alert(document.domain)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-6275.yaml | POC Details |
| 3 | Nov 24, 2023 — A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. | https://github.com/LelioCosta/FLUIG-Vulnerabilidade-CVE-2023-6275 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet