OSV 1.4.0 · unreviewed · 修改于 2022-01-06 08:00
发布时间
2021-12-27 08:00
GitHub 审查时间
—
NVD 发布时间
2021-12-26 23:15
源文件
advisories/unreviewed/2021/12/GHSA-988v-mhrc-mc5v/GHSA-988v-mhrc-mc5v.json
Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The attacker can access the system, by using the XSS-reflected method, and then can store information by injecting the admin account on this system.
该公告没有提供结构化的受影响软件包信息。