Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
SAMSUNG MagicINFO 9 Server 安全漏洞
Vulnerability Description
SAMSUNG MagicINFO 9 Server是韩国三星(SAMSUNG)公司的一个企业级数字标牌内容管理与设备监控平台。 SAMSUNG MagicINFO 9 Server 21.1090.1之前版本存在安全漏洞,该漏洞源于未经身份验证即可上传HTML文件,可能导致存储型跨站脚本攻击和账户接管。
CVSS Information
N/A
Vulnerability Type
N/A