Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-4377: main/README.md at main · mengdeyin/main

A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Contact Information Page. The manipulation of the argument Make a Call leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215197 was assigned to this vulnerability.

CVE
#xss#vulnerability#web#php

Permalink

1 contributor

Users who have contributed to this file

XSS vulnerability exists in S-CMS government station building system

Vulnerability description:

XSS vulnerability exists in S-CMS government station building system

Test process:

  1. Download the latest government station CMS-v5.0 locally_ build20220328

  2. Use phpstudy to build a local

  3. The test uses admin as the background management page path Visit the background management page to log in and select “联系方式”

Insert xss statement at the place of “make a call”

Accessing web pages

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda