Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Stored XSS vulnerability in Host navigator widget maintenance tooltip
Vulnerability Description
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Zabbix 跨站脚本漏洞
Vulnerability Description
Zabbix是Zabbix公司的一套开源的监控系统。该系统支持网络监控、服务器监控、云监控和应用监控等。 Zabbix存在跨站脚本漏洞,该漏洞源于经过身份验证的非超级管理员可以创建包含JavaScript有效负载的维护期,任何打开该维护期工具提示的用户都会执行该有效负载,可能导致攻击者根据打开工具提示的用户执行未授权操作。
CVSS Information
N/A
Vulnerability Type
N/A