CLink Office 2.0 is vulnerable to cross-site scripting in the index page of the management console and allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view