Metrics
Affected Vendors & Products
Tue, 20 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Technical-laohu
Technical-laohu mpay |
|
| Vendors & Products |
Technical-laohu
Technical-laohu mpay |
Mon, 19 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. | |
| Title | technical-laohu mpay User Center cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-01-19T11:02:05.822Z
Updated: 2026-01-20T21:28:25.158Z
Reserved: 2026-01-18T13:59:43.860Z
Link: CVE-2026-1151
Updated: 2026-01-20T21:28:22.763Z
Status : Received
Published: 2026-01-19T11:15:50.047
Modified: 2026-01-19T11:15:50.047
Link: CVE-2026-1151
No data.
ReportizFlow