Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. 的“图书馆信息与文档自动化程序”中,由于在网页生成过程中未正确对用户输入进行中和(neutralization),导致存在跨站脚本(XSS)漏洞,该漏洞可针对 HTML 属性发起 XSS 攻击。 此问题影响“图书馆信息与文档自动化程序”v22.2 版本之前的版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. | Library Information and Document Automation Program | < v22.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. | Library Information and Document Automation Program | 0 ~ v22.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet