Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HortusFox 安全漏洞
Vulnerability Description
HortusFox是HortusFox公司的一个免费且开源的自托管植物管理器系统。 HortusFox v4.4存在安全漏洞,该漏洞源于对/controller/admin.php端点中参数email的错误操作导致跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A