漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint
Vulnerability Description
CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during draft creation. Attackers can submit a malicious HTML payload as a draft title through the drafts creation endpoint, which is persisted to the database without escaping and later rendered as raw HTML in the admin drafts listing, enabling administrator session compromise, cookie theft, and forged authenticated requests.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Owen Peredo Diaz CamaleonCMS 跨站脚本漏洞
Vulnerability Description
Owen Peredo Diaz CamaleonCMS是Owen Peredo Diaz个人开发者的一款内容管理系统。 Owen Peredo Diaz CamaleonCMS 2.9.1及之前版本存在跨站脚本漏洞,该漏洞源于对post title参数输入清理不当,可能允许经过身份验证的低权限用户注入未清理的HTML有效载荷,导致存储型跨站脚本攻击,在管理员浏览器中执行任意JavaScript,造成管理员会话劫持、cookie窃取和伪造认证请求。
CVSS Information
N/A
Vulnerability Type
N/A