We found results for “”
CVE-2023-46394
Good to know:
Date: October 26, 2023
A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
Upgrade Version
Upgrade to version hsk99/push-service - no_fix;zoujingli/think-plugs-static - v1.0.57;zoujingli/think-plugs-static - v1.0.74;hsk99/transfer-statistics - no_fix;jiannei/layadmin - v2.3.1;jiannei/layadmin - dev-analysis-1bMmEv;jiannei/layadmin - dev-analysis-QMgx2p;jiannei/layadmin - dev-analysis-bQnBn4;taoser/taoler - v2.3.6;taoser/taoler - dev-dependabot/composer/phpmailer/phpmailer-6.4.1;taoser/taoler - v1.9.15;taoser/taoler - no_fix;funadmin/funadmin - v5.x-dev;funadmin/funadmin - v2.1.0;funadmin/funadmin - dev-remotes/origin/v3.0;colasoft/colaphp - v1.0.0;HaveMvc.Web - no_fix;jiannei/pear-admin - v1.0.0;hsk99/webman-admin - no_fix;org.webjars:layui:2.8.12;org.webjars.npm:layui:2.8.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


