漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter
Vulnerability Description
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the ticket_id GET parameter directly into a hidden input field VALUE attribute. Attackers can craft a malicious URL containing a JavaScript payload in the ticket_id parameter that executes in the victim's browser when the URL is visited.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
tickets 跨站脚本漏洞
Vulnerability Description
tickets是Open ISES开源的一款公共安全调度管理与追踪应用。 Tickets 3.44.2之前版本存在跨站脚本漏洞,该漏洞源于routes_nm.php中存在反射型跨站脚本漏洞,可能导致已认证攻击者通过ticket_id GET参数传递未清理值直接注入隐藏输入字段VALUE属性,从而注入任意JavaScript。
CVSS Information
N/A
Vulnerability Type
N/A