Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-19295 PoC — Jeesns 跨站脚本漏洞

Source
Associated Vulnerability
Title:Jeesns 跨站脚本漏洞 (CVE-2020-19295)
Description:福州凌夕网络科技 JEESNS是中国福州凌夕网络科技公司的一款基于JAVA企业级平台研发的社交管理系统。依托企业级JAVA的高效、安全、稳定等优势,开创国内JAVA版开源SNS先河。数据库使用MYSQL,全部源代码开放。 Jeesns 1.4.2存在安全漏洞,该漏洞允许攻击者可利用该漏洞执行任意的web脚本或HTML。
Description
Jeesns 1.4.2 is vulnerable to reflected cross-site scripting in the /weibo/topic component and allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.
File Snapshot

id: CVE-2020-19295 info: name: Jeesns 1.4.2 - Cross-Site Scripting author: pikpikcu severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.