Joomla 扩展程序 - digital-peak.com - DP Calendar 7.0.0 至 10.11.2 版本中的认证且拥有特权的存储型 XSS 漏洞 - 位置标题(Location title)在未转义的情况下直接渲染到 属性中,从而导致 XSS 漏洞;触发该漏洞需要用户在 DPCalendar 中具备“创建”权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| digital-peak.com | DP Calendar extension for Joomla | 7.0.0-10.11.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet