jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicious JavaScript scripts by modifying the request package.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/Cherry-toto/jizhicms/issues/86 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-05-19T00:00:00
Updated: 2024-08-02T15:03:27.110Z
Reserved: 2023-04-29T00:00:00
Link: CVE-2023-31862
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-19T13:15:08.920
Modified: 2024-11-21T08:02:20.827
Link: CVE-2023-31862
Redhat
No data.