漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
HumHub: XSS in Button component
Vulnerability Description
HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0. Due to inconsistent output encoding at several points within the software, malicious scripts could be injected and executed in the context of the user's browser. This issue has been patched in version 1.18.1.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
HumHub 跨站脚本漏洞
Vulnerability Description
HumHub是HumHub开源的一套基于Yii PHP框架编写的开源社交网络软件。 HumHub 1.18.0版本存在跨站脚本漏洞,该漏洞源于Button组件中输出编码不一致,可能导致恶意脚本在用户浏览器环境中注入和执行。
CVSS Information
N/A
Vulnerability Type
N/A