关于CVE-2022-43097的所有详细信息
软件:Phpgurukul User Registration & User Management System v3.0
软件链接:https://phpgurukul.com/user-registration-login-and-user-management-system-with-admin-panel/
描述:Phpgurukul User Registration & User Management System v3.0 被发现存在多处存储型跨站脚本(XSS)漏洞,这些漏洞通过注册表单和登录页面的名字和姓氏参数触发。
漏洞类型:存储型跨站脚本(XSS)
受影响的产品代码库:User Registration & Login and User Management System With admin panel
受影响组件:http://127.0.0.1/login.php, http://127.0.0.1/welcome.php
攻击类型:远程
攻击向量:恶意有效载荷以名字和姓氏的形式保存到web服务器上。