漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Stored Cross-site Scripting in Pentestify user account deletion via unescaped username
Vulnerability Description
Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Thomas O´neil Álvarez Pentestify 跨站脚本漏洞
Vulnerability Description
Thomas O´neil Álvarez Pentestify是Thomas O´neil Álvarez个人开发者的一款漏洞扫描产品。 Thomas O´neil Álvarez Pentestify 1.1.1之前版本存在存储型跨站脚本漏洞,该漏洞源于用户管理组件中前端使用escapeHTML()转义用户名后插入删除按钮的onclick属性,但浏览器在JavaScript引擎解析属性值前进行HTML解码,导致编码的单引号逃逸字符串并注入任意JavaScript,具有认证权限的攻击者可通过特制用户名在
CVSS Information
N/A
Vulnerability Type
N/A