Shopclass 6.2.0 之前版本中存在一个存储型跨站脚本(XSS)漏洞,允许自行注册的非管理员用户在启用前端 TinyMCE 编辑器时,向商品描述中注入恶意脚本。攻击者可以提交恶意的 JavaScript 代码,ItemActions.php 会在未进行标签过滤的情况下直接保存该代码,导致任何浏览该商品的访问者在页面加载时,在其站点上下文中执行该恶意脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mindstellar | shopclass | 0 ~ 6.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet