漏洞标题
SourceCodester学校日志管理系统跨站脚本攻击
漏洞描述信息
发现了一个漏洞存在于SourceCodester School Log Management System 1.0中,该漏洞被评估为存在问题。此问题影响了文件/admin/ajax.php?action=save_student的部分未知处理过程。通过操纵参数名称,可以导致跨站脚本攻击。攻击可以在远程进行。漏洞的利用信息已公开,并可能被利用。此漏洞被分配了VDB-272789的标识。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
SourceCodester School Log Management System cross site scripting
漏洞描述信息
A vulnerability was found in SourceCodester School Log Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/ajax.php?action=save_student. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272789 was assigned to this vulnerability.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
SourceCodester School Log Management System 安全漏洞
漏洞描述信息
SourceCodester School Log Management System是SourceCodester公司的一款学校日志管理系统。 SourceCodester School Log Management System 1.0 版本存在安全漏洞,该漏洞源于 /admin/ajax.php?action=save_student 页面的 name 函数包含一个跨站脚本漏洞。
CVSS信息
N/A
漏洞类别
其他