漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter
Vulnerability Description
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the frm_call GET parameter directly into page output. Attackers can craft a malicious URL containing a JavaScript payload in the frm_call parameter that executes in the victim's browser when the URL is visited.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
tickets 跨站脚本漏洞
Vulnerability Description
tickets是Open ISES开源的一款公共安全调度管理与追踪应用。 Tickets 3.44.2之前版本存在跨站脚本漏洞,该漏洞源于opena.php中存在反射型跨站脚本漏洞,可能导致已认证攻击者通过frm_call GET参数传递未清理值直接注入页面输出,从而注入任意JavaScript。
CVSS Information
N/A
Vulnerability Type
N/A