WordPress 插件 SureDash – Community, Courses & Member Dashboard 存在存储型 DOM 驱动型跨站脚本(DOM-Based Stored Cross-Site Scripting)漏洞。该漏洞影响 1.12.1 及更早版本,原因是缺乏足够的输入清理和输出转义。该漏洞出现在社区帖子内容的图片“alt”属性中。 这使得具有订阅者及以上权限的已认证攻击者能够在页面中注入任意网页脚本,当其他用户访问包含恶意脚本的页面时,这些脚本将被执行。 该漏洞的实体编码有效载荷能够
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| brainstormforce | SureDash – Community, Courses & Member Dashboard | ≤ 1.12.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| brainstormforce | SureDash – Community, Courses & Member Dashboard | 0 ~ 1.12.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet