漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Stored Cross-site Scripting Vulnerability via Malicious File Names in GroupOffice
Vulnerability Description
Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present in the file upload mechanism of Group Office. It allows an attacker to execute arbitrary JavaScript code by embedding it within a file's name. For instance, using a filename such as “><img src=x onerror=prompt('XSS')>.jpg” triggers the vulnerability. When this file is uploaded, the JavaScript code within the filename is executed. This issue has been addressed in version 6.8.29. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Group Office CRM 跨站脚本漏洞
Vulnerability Description
Group Office CRM是一个应用软件。与同事和客户在线共享项目,日历,文件和电子邮件。易于使用且可完全自定义。 Group Office CRM 6.8.28版本存在跨站脚本漏洞,该漏洞源于Upload功能存在存储型跨站脚本(XSS)漏洞。
CVSS Information
N/A
Vulnerability Type
N/A