Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the password parameter at /mail/MailController.java.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
oa_system 安全漏洞
Vulnerability Description
oa_system是hailey个人开发者的一个面向组织的日常运作和管理,员工及管理者使用的应用系统。 oa_system v2025.01.01之前版本存在安全漏洞,该漏洞源于对文件/mail/MailController.java中参数password的输入清理不当,可能导致跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A