CNNVD-202509-1657 Information
Sep 11, 2025
cve
CNNVD ID
CNNVD-202509-1657
Related CVE
- CNNVD Published: 2025-09-11
Description (Chinese)
openDCIM是openDCIM开源的一个数据中心库存管理(DCIM)应用程序。 openDCIM 23.04版本存在安全漏洞,该漏洞源于对文件/scripts/uploadifive.php中参数Filedata的错误操作,可能导致跨站脚本攻击。
Description (English)
OpenDCIM is an open-source data centre inventory management (DCIM) application. An openDCIM 23.04 version contains a security loophole that stems from an error in the application of the parameter Filedata in the document/scripts/uploadlive.php, which could result in a cross-site script attack.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
openDCIM
Published
2025-09-11
Last Modified
2026-02-24
References
https://github.com/lam-sec/openDCIMpoc https://vuldb.com/?id.323613 https://vuldb.com/?submit.642716 https://vuldb.com/?ctiid.323613 https://access.redhat.com/security/cve/cve-2025-10253
Share on: