FOGProject是FOGProject组织开源的一个免费的开源网络计算机克隆和管理解决方案。可用于部署和管理任何桌面操作系统。 FOGProject 1.5.10.1832之前版本和1.6.0-beta.2313之前版本存在跨站脚本漏洞,该漏洞源于fogpage.class.php文件中的buildRow()方法使用str_replace()替换数据值至HTML表格单元格模板时未进行HTML转义,可能导致未经身份验证的攻击者通过POST恶意库存值至/service/inventory.php,当管理员
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FOGProject | fogproject | < 1.5.10.1832 |
affected |
< 1.6.0-beta.2313 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FOGProject | fogproject | < 1.5.10.1832 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47688 | 8.2 HIGH | FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of |
| CVE-2026-47685 | 7.3 HIGH | FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host |
| CVE-2026-47687 | 7.3 HIGH | FOGProject has stored XSS via unescaped option label in selectForm() accessible from unaut |
No comments yet