CNNVD-202602-018 Information
Feb 01, 2026
cve
CNNVD ID
CNNVD-202602-018
Related CVE
- CNNVD Published: 2026-02-01
Description (Chinese)
Knap Advanced PHP Login是Knap公司的一个身份验证系统脚本。 Knap Advanced PHP Login 3.1.3版本存在跨站脚本漏洞,该漏洞源于name参数存在存储型跨站脚本,可能导致会话劫持和持久性钓鱼攻击。
Description (English)
Knap Advanced PHP Login is a script of Knap ’ s identification system. Version Knap Advanced PHP Login 3.1.3 has a cross-site script loophole, which stems from the presence of a stored cross-site script of name parameters, which may lead to conversational hijacking and persistent fishing attacks.
Hazard Level
High
Vulnerability Type
跨站脚本
Affected Vendor
Knap
Published
2026-02-01
Last Modified
2026-02-24
References
https://laravel-vuejs.com/ https://www.vulncheck.com/advisories/knap-advanced-php-login-persistent-cross-site-scripting-via-name-parameter https://www.vulnerability-lab.com/get_content.php?id=2307
Share on: