在 Bimser Solution Software Trade Inc. 的 eBA Plus 文档与工作流管理系统中,存在网页生成过程中输入净化不当导致的“跨站脚本(XSS)”漏洞,该漏洞可导致存储型 XSS 攻击。 此问题影响 eBA Plus 文档与工作流管理系统:受影响的版本为 6.7.141 之前的所有版本,直至 10.0.11(不含 10.0.11)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bimser Solution Software Trade Inc. | eBA Plus Document and Workflow Management System | 6.7.141 ~ 10.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85134 | 8.8 HIGH | Arbitrary File Upload Leading to Remote Command Execution in Bimser's eBA Plus |
| CVE-2026-82915 | 6.5 MEDIUM | Path Traversal in Bimser Solution Software's eBA Plus |
No comments yet