Mario Pentestify是Mario个人开发者的一款云计算渗透测试产品。 Mario Pentestify 1.1.0之前版本存在跨站脚本漏洞,该漏洞源于客户端报告渲染函数(js/app.js中的renderPreview、renderEditor、renderAuditData)中的存储型跨站脚本问题,可能导致远程、经过身份验证的攻击者通过存储在finding images数组或report client_logo数组中的有效载荷,在查看受影响报告用户的浏览器中执行任意JavaScript。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| maalfer | Pentestify | < 1.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| maalfer | Pentestify | 0 ~ 1.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet