Dismissed
(no matching packages found)
Activity log
- Created & dismissed (no matching packages found) suggestion
yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The …
yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.
References
Affected products
n/a
- ==n/a