OSV 1.4.0 · github-reviewed · 修改于 2026-05-07 09:20
发布时间
2026-05-01 02:30
GitHub 审查时间
2026-05-07 09:20
NVD 发布时间
2026-05-01 02:16
源文件
advisories/github-reviewed/2026/04/GHSA-fqcw-2xhj-p63g/GHSA-fqcw-2xhj-p63g.json
Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer through version 3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the getInputStream() or getReader() functions.