Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTML and JavaScript strings. This allows low-privilege attackers to construct comment content or request parameters and execute arbitrary JavaScript code when the victim opens the editing pop-up.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DzzOffice 安全漏洞
Vulnerability Description
DzzOffice是大桌子(DzzOffice)公司的一个可提供在线协同办公套件功能的平台。提供在线文档、表格、网盘、演示等功能。 DzzOffice 2.3.x版本存在安全漏洞,该漏洞源于评论编辑模板未正确转义用户数据,可能导致跨站脚本。
CVSS Information
N/A
Vulnerability Type
N/A