dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site...
Moderate severity
Unreviewed
Published
Dec 4, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 3, 2021
Published to the GitHub Advisory Database
Dec 4, 2021
Last updated
Feb 1, 2023
dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of exit function will be print for the user exit(json_encode($return)).
References