Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Stored Cross-Site Scripting (XSS) vulnerability in Stel Order
Vulnerability Description
Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper input sanitization allows an attacker to inject malicious code that is persistently stored in the database. When other users or administrators access the affected sections, the code executes in their browsers, enabling the theft of session cookies and account hijacking.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
STEL Order 跨站脚本漏洞
Vulnerability Description
STEL Order是西班牙STEL公司的一个面向中小企业的ERP、CRM与在线计费管理平台。 STEL Order 3.25.1及之前版本存在跨站脚本漏洞,该漏洞源于对legalName和employeeID参数清理不足,可能导致攻击者注入恶意代码,导致会话cookie窃取和账户劫持。
CVSS Information
N/A
Vulnerability Type
N/A