Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with administrative privileges can inject malicious JavaScript code into the “Help button url” setting within the admin panel. The injected payload is stored and executed when any authenticated user clicks the Help button, potentially leading to session hijacking, information disclosure, privilege escalation, and unauthorized administrative actions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Perch CMS 安全漏洞
Vulnerability Description
Perch CMS是Perch公司的一个内容管理系统。 Perch CMS 3.2版本存在安全漏洞,该漏洞源于管理面板中Help button url设置存在存储型跨站脚本,可能导致会话劫持、信息泄露、权限提升或未经授权的管理操作。
CVSS Information
N/A
Vulnerability Type
N/A