Grav 1.7.50.2 允许管理员通过“主页编辑器”注入 JavaScript。注意:该漏洞对于存储型 XSS(跨站脚本)的实际影响存在争议,因为管理员本身就被允许修改模板、安装插件以及上传其他可执行内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet