漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GFI MailEssentials AI < 22.4 Keyword Filtering Rule Stored XSS
Vulnerability Description
GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Keyword Filtering rule creation workflow. An authenticated user can supply HTML/JavaScript in the ctl00$ContentPlaceHolder1$pv1$TXB_RuleName parameter to /MailEssentials/pages/MailSecurity/contentchecking.aspx, which is stored and later rendered in the management interface, allowing script execution in the context of a logged-in user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
GFI MailEssentials AI 安全漏洞
Vulnerability Description
GFI MailEssentials AI是美国GFI开源的一个反垃圾邮件与数据泄露防护软件。 GFI MailEssentials AI 22.4之前版本存在安全漏洞,该漏洞源于关键词过滤规则创建流程中存在存储型跨站脚本,可能导致在登录用户环境中执行脚本。
CVSS Information
N/A
Vulnerability Type
N/A