Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Stored Cross-Site Scripting in URVE Smart Office
Vulnerability Description
URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of authentication. This issue was fixed in version 1.1.24.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
URVE Smart Office 跨站脚本漏洞
Vulnerability Description
URVE Smart Office是波兰URVE Smart Office公司的一套智能办公资源管理系统。 URVE Smart Office 1.1.24之前版本存在跨站脚本漏洞,该漏洞源于报告问题功能中存在存储型跨站脚本,可能导致恶意载荷执行。
CVSS Information
N/A
Vulnerability Type
N/A