Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in XunRuiCMS version 4.7.1. The vulnerability exists due to insufficient validation of SVG file uploads in the dayrui/Fcms/Library/Upload.php component, allowing attackers to inject malicious JavaScript code that executes when the uploaded file is viewed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
XunRuiCMS 安全漏洞
Vulnerability Description
XunRuiCMS(迅睿CMS)是XunRuiCMS个人开发者的一个内容管理系统。 XunRuiCMS 4.7.1版本存在安全漏洞,该漏洞源于SVG文件上传验证不足,可能导致存储型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A