Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-32853 PoC — erxes 跨站脚本漏洞

Source
Associated Vulnerability
Title:erxes 跨站脚本漏洞 (CVE-2021-32853)
Description:erxes是erxes开源的一个开源 Hubspot/Qualtrics 替代方案。使 SaaS 提供商和数字营销机构/开发商能够为其整个业务创造独特的体验。 erxes 0.22.3及之前版本存在安全漏洞,该漏洞源于存在跨站脚本漏洞,攻击者利用该漏洞可以导致客户端代码执行。
Description
Erxes before 0.23.0 contains a cross-site scripting vulnerability. The value of topicID parameter is not escaped and is triggered in the enclosing script tag.
File Snapshot

id: CVE-2021-32853 info: name: Erxes <0.23.0 - Cross-Site Scripting author: dwisiswant0 sever ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.