漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php
Vulnerability Description
Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The create.blade.php template renders customer name fields without the Vue.js v-pre directive, causing Vue.js to evaluate stored template expressions as live JavaScript when an administrator opens the Create Order page for the affected customer.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Bagisto 跨站脚本漏洞
Vulnerability Description
Bagisto Bagisto是Bagisto组织开源的一款电子商务平台开发框架。 Bagisto 2.4.4之前版本存在跨站脚本漏洞,该漏洞源于客户端模板注入,允许未经身份验证的攻击者在注册客户账户时,在名字或姓氏字段中插入恶意有效载荷,当管理员打开受影响客户的创建订单页面时,Vue.js会评估存储的模板表达式作为实时JavaScript,从而在管理员浏览器中执行任意JavaScript。
CVSS Information
N/A
Vulnerability Type
N/A