关联漏洞
标题:Creative Item Academy LMS 跨站脚本漏洞 (CVE-2023-4973)Description:Creative Item Academy LMS是Creative Item公司的一个基于在线课程的学习管理系统。 Creative Item Academy LMS 6.2(Windows)版本存在跨站脚本漏洞,该漏洞源于组件 GET Parameter Handler 中的/academy/tutor/filter 存在未知函数,通过参数 searched_word、searched_tution_class_type[]、searched_price_type[]、searched_duratio
Description
A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument searched_word/searched_tution_class_type[]/searched_price_type[]/searched_duration[] leads to cross site scripting. The attack can be launched remotely.
文件快照
id: CVE-2023-4973
info:
name: Academy LMS 6.2 - Cross-Site Scripting
author: ritikchaddha,princ
...
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮件到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对 POC 代码进行快照,为了长期维护,请考虑为本地 POC 付费/捐赠,感谢您的支持。