CNNVD-202602-018 Information

CNNVD ID

CNNVD-202602-018

CVE-2022-50940

  • CNNVD Published: 2026-02-01

Description (Chinese)

Knap Advanced PHP Login是Knap公司的一个身份验证系统脚本。 Knap Advanced PHP Login 3.1.3版本存在跨站脚本漏洞,该漏洞源于name参数存在存储型跨站脚本,可能导致会话劫持和持久性钓鱼攻击。

Description (English)

Knap Advanced PHP Login is a script of Knap ’ s identification system. Version Knap Advanced PHP Login 3.1.3 has a cross-site script loophole, which stems from the presence of a stored cross-site script of name parameters, which may lead to conversational hijacking and persistent fishing attacks.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

Knap

Published

2026-02-01

Last Modified

2026-02-24

References

https://laravel-vuejs.com/ https://www.vulncheck.com/advisories/knap-advanced-php-login-persistent-cross-site-scripting-via-name-parameter https://www.vulnerability-lab.com/get_content.php?id=2307

Share on: