漏洞标题
Zenvia Movidesk 新建工单处存在跨站脚本漏洞
漏洞描述信息
在Zenvia Movidesk的25.01.22版本中发现了一个被归类为问题的漏洞,该漏洞影响组件New Ticket Handler的未知部分。该漏洞是由于subject参数的操纵导致的跨站脚本攻击。可以在远程发起该攻击。该漏洞的利用方法已经公开,存在被利用的风险。升级到版本25.01.22.245a473c54可以解决此问题,建议升级受影响的组件。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
Zenvia Movidesk New Ticket cross site scripting
漏洞描述信息
A vulnerability classified as problematic has been found in Zenvia Movidesk up to 25.01.22. This affects an unknown part of the component New Ticket Handler. The manipulation of the argument subject leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 25.01.22.245a473c54 is able to address this issue. It is recommended to upgrade the affected component.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)