漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Agile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_name
Vulnerability Description
The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Agile Logix Store Locator WordPress 跨站脚本漏洞
Vulnerability Description
Agile Logix Store Locator WordPress是Agile Logix公司的一款WordPress店铺定位插件。 Agile Logix Store Locator WordPress 1.6.9之前版本存在跨站脚本漏洞,该漏洞源于商店Logo元数据在存储和后台管理页面输出时未进行充分的输入过滤和输出转义,可能导致高权限用户实施存储型跨站脚本攻击,即使禁用了unfiltered_html权限仍可利用该漏洞。
CVSS Information
N/A
Vulnerability Type
N/A