以下是对该漏洞描述信息的中文翻译: Roskus Prospero Flow CRM 5.4.4 版本之前的邮件模块中存在存储型跨站脚本漏洞(CWE-79),允许远程的低权限认证用户在另一个用户的浏览器中执行任意 JavaScript 代码,包括针对管理员的攻击。攻击者可通过将恶意载荷嵌入电子邮件正文,并持久化存储且未进行消毒处理,当收件人打开邮件时,该载荷以 {!! $email->body !!} 的形式被未转义地渲染,从而导致会话被劫持和账户接管。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Roskus | Prospero Flow CRM | 1.0.0< 5.4.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Roskus | Prospero Flow CRM | 1.0.0 ~ 5.4.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet