Stormshield 的 Web 管理面板中存在存储型跨站脚本(Stored XSS)漏洞。 要利用该漏洞,具有相应权限的 SNS 管理员必须在 web 服务管理界面的某个用户组的备注(comments)字段中注入恶意脚本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Stormshield | Stormshield Network Security | 4.8.0≤ 4.8.16 |
affected |
5.0.0≤ 5.0.6 |
affected | ||
4.8.17 |
unaffected | ||
5.0.7 |
unaffected | ||
5.1.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Stormshield | Stormshield Network Security | 4.8.0 ~ 4.8.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet