WordPress 插件 "The Events Manager - Calendar, Bookings, Tickets, and more!" 在包括 7.3.3 及之前所有版本中,存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞源于在存储事件属性值时输入净化不充分(仅使用了 而未进行任何过滤),以及在渲染 占位符时缺少输出转义。这使得拥有 Author(作者)及以上权限的已认证攻击者,或在启用匿名事件提交功能时的未认证攻击者,能够注入任意的 Web 脚本。这
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| netweblogic | Events Manager – Calendar, Bookings, Tickets, and more! | 0 ~ 7.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet