Concrete CMS 社区商店(Community Store)2.7.8 之前的版本在结账视图和管理员视图中渲染客户提供的订单字段时,未进行 HTML 转义。未经身份验证的攻击者可以在账单姓名、邮箱或电话字段中存储脚本载荷,这些载荷将在已认证的经理会话中执行,从而用于创建非法账户或泄露数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| concretecms-community-store | community_store | < 2.7.8 |
affected |
2.7.8 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| concretecms-community-store | community_store | 0 ~ 2.7.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet