WEMS Enterprise Manager - Cross-Site Scripting
WEMS Enterprise Manager contains a cross-site scripting vulnerability via the /guest/users/forgotten endpoint and the email parameter, which allows a remote attacker to inject arbitrary JavaScript into the response return by the server.
wems_managerPoC 已收录
CVSS7.2