W CMS(版本范围:从早期版本到 3.18.0)存在一个存储型跨站脚本(XSS)漏洞,未授权攻击者可通过登录用户的用户名字段和访客评论的网站字段注入恶意脚本。攻击者可以提交失败的登录请求,这些请求会被未转义地显示在管理员日志查看器(adminlog.php)中;或者将恶意评论网址回显到 editrightbar.php 页面中的 href 属性中,从而以管理员或编辑者权限执行脚本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vincent-peugnet | wcms | ≤ 3.18.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| vincent-peugnet | wcms | 0 ~ 3.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet