漏洞标题
FlatPress XML File Handler/MD File 管理员上传者.uploader.php 跨站脚本攻击
漏洞描述信息
FlatPress XML文件处理器/MD文件admin.uploader.php onupload跨站脚本
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
N/A
漏洞标题
FlatPress XML File Handler/MD File admin.uploader.php onupload cross site scripting
漏洞描述信息
A vulnerability classified as problematic was found in FlatPress. This vulnerability affects the function onupload of the file admin/panels/uploader/admin.uploader.php of the component XML File Handler/MD File Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 3cc223dec5260e533a84b5cf5780d3a4fbf21241. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217000.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
FlatPress 跨站脚本漏洞
漏洞描述信息
FlatPress是FlatPress社区的一个基于Php无需数据库支持的博客建站系统。 FlatPress存在跨站脚本漏洞,该漏洞源于组件XML File Handler/MD File Handler中admin/panels/uploader/admin.uploader.php文件的上传功能存在问题,会导致跨站脚本。
CVSS信息
N/A
漏洞类别
跨站脚本