OSV 1.4.0 · unreviewed · 修改于 2022-02-18 08:00
发布时间
2022-02-11 08:00
GitHub 审查时间
—
NVD 发布时间
2022-02-10 07:15
源文件
advisories/unreviewed/2022/02/GHSA-9r8c-8qcg-679m/GHSA-9r8c-8qcg-679m.json
Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to compromise the administrator session.
该公告没有提供结构化的受影响软件包信息。