漏洞标题
多个经过身份验证的存储型跨站脚本漏洞
漏洞描述信息
在 "bestinformed Web" 应用程序中,某些用户输入未经过正确过滤。这导致了多个经认证的存储型跨站脚本漏洞。攻击者可以利用 "经认证的存储型跨站脚本" 将 JavaScript 代码注入到其他用户的会话中,从而破坏这些用户的会话。这些用户可能具有比攻击者更高的权限,从而实现横向移动。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
Multiple Authenticated Stored Cross-Site Scripting
漏洞描述信息
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is able to compromise the sessions of other users on the server by injecting JavaScript code into their session using an "Authenticated Stored Cross-Site Scripting". Those other users might have more privileges than the attacker, enabling a form of horizontal movement.
CVSS信息
N/A
漏洞类别
输入验证不恰当