Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php
Vulnerability Description
Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The create.blade.php template renders customer name fields without the Vue.js v-pre directive, causing Vue.js to evaluate stored template expressions as live JavaScript when an administrator opens the Create Order page for the affected customer.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Bagisto 跨站脚本漏洞
Vulnerability Description
Bagisto Bagisto是Bagisto组织开源的一款电子商务平台开发框架。 Bagisto 2.4.4之前版本存在跨站脚本漏洞,该漏洞源于客户端模板注入,允许未经身份验证的攻击者在注册客户账户时,在名字或姓氏字段中插入恶意有效载荷,当管理员打开受影响客户的创建订单页面时,Vue.js会评估存储的模板表达式作为实时JavaScript,从而在管理员浏览器中执行任意JavaScript。
CVSS Information
N/A
Vulnerability Type
N/A