Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
DOM-based Cross-Site Scripting in OutSystems Service Center
Vulnerability Description
OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server. This issue was fixed in OutSystems Service Center version 11.41.2
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Outsystems Service Center 跨站脚本漏洞
Vulnerability Description
Outsystems Service Center是美国Outsystems公司的一个应用服务器运维管理平台。 Outsystems Service Center 11.41.2之前版本存在跨站脚本漏洞,该漏洞源于基于DOM的跨站脚本,低权限攻击者可通过上传包含JavaScript代码的恶意文件名的文件进行利用。
CVSS Information
N/A
Vulnerability Type
N/A