Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser context.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FormCMS 安全漏洞
Vulnerability Description
FormCMS是formcms个人开发者的一个页面设计器。 FormCMS 0.5.5版本存在安全漏洞,该漏洞源于头像上传功能存在存储型跨站脚本,可能导致特权用户浏览器环境中执行恶意脚本。
CVSS Information
N/A
Vulnerability Type
N/A