Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Stored XSS in PluXml CMS
Vulnerability Description
PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious payload, which will be executed when a victim clicks the link associated with the uploaded image. In version 5.9.0-rc7 clicking the link associated with the uploaded image doesn't execute malicious code but directly accessing the file will still execute the embedded payload. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only versions 5.8.21 and 5.9.0-rc7 were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
PluXml CMS 跨站脚本漏洞
Vulnerability Description
PluXml CMS是法国PluXml公司的一个无数据库内容管理系统。 PluXml CMS 5.8.21版本和5.9.0-rc7版本存在跨站脚本漏洞,该漏洞源于文件上传功能存在存储型跨站脚本,可能导致执行恶意有效载荷。
CVSS Information
N/A
Vulnerability Type
N/A