在端点 的通知模板功能中,存在一个存储型跨站脚本(XSS)漏洞。拥有管理员权限的用户可以输入恶意的 HTML 内容,这些内容会被存储下来,并在其他管理员访问模板自定义视图时,未经过适当的过滤(净化)就直接显示出来。这使得恶意 JavaScript 代码能够在应用的安全上下文中执行,从而可能窃取或破坏其他拥有管理员权限用户的会话。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OCS Inventory NG | Ocsreports | 2.12.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OCS Inventory NG | Ocsreports | 2.12.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76174 | 9.4 CRITICAL | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76176 | 8.6 HIGH | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76175 | 8.6 HIGH | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76177 | 7.1 HIGH | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
No comments yet