BeeTienda电子商务平台最新版演示版本中存在反射型跨站脚本(XSS)漏洞。该漏洞源于产品列表端点的“search”参数未对用户输入数据进行适当 sanitization(过滤/净化)。当恶意载荷通过“search”参数传入时,会在HTML响应中以不安全的方式被显示,从而导致攻击者能够在受害者浏览器中任意执行JavaScript代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BeeTienda | eCommerce Platform | < November 2025 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BeeTienda | eCommerce Platform | 0 ~ November 2025 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet