Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Frappe LMS: HTML injection in user-controlled metadata
Vulnerability Description
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Vulnerability Title
Frappe Learning Management System 注入漏洞
Vulnerability Description
Frappe Learning Management System是Frappe开源的一个易于使用的开源学习管理系统。 Frappe Learning Management System 2.53.0之前版本存在注入漏洞,该漏洞源于经过身份验证的用户可在某些用户可编辑字段中提供特制内容,导致页面元数据中显示时访问者浏览器导航至攻击者选择的URL。
CVSS Information
N/A
Vulnerability Type
N/A