漏洞标题
Goobi viewer 核心在用户评论中具有跨站脚本漏洞
漏洞描述信息
Goobi viewer Core的用户评论中存在跨站脚本漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
N/A
漏洞标题
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Comments
漏洞描述信息
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of malicious script code in the user's browser when displaying the comment. The vulnerability has been fixed in version 23.03.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
Intranda Goobi Viewer Core 跨站脚本漏洞
漏洞描述信息
Intranda Goobi Viewer Core是德国Intranda公司的一套基于Web的数字图书馆系统。 Intranda Goobi Viewer Core 23.03之前版本存在跨站脚本漏洞,该漏洞源于在用户评论功能中存在跨站脚本(XSS)漏洞。攻击者可利用该漏洞创建特制的评论,从而在用户浏览器中执行恶意脚本代码。
CVSS信息
N/A
漏洞类别
跨站脚本