漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
Archer Platform 安全漏洞
Vulnerability Description
Archer Platform是Archer公司的一个现代综合风险管理解决方案。 Archer Platform 6 2024.06之前版本存在安全漏洞,该漏洞源于容易受到存储型跨站脚本攻击,攻击者将恶意代码存储在受信任的应用程序数据存储中,当用户通过浏览器访问时,恶意代码会在易受攻击的应用程序环境中由Web浏览器执行。
CVSS Information
N/A
Vulnerability Type
N/A