天下漏洞,尽知其名
MEDIUM

CVE-2026-101111 Joomla Book Library 反射型跨站脚本漏洞

MEDIUM
暂无 CVSS 评分
原始情报

Joomla Extension – ordasoft.com – Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 – The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $_REQUEST["title"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow.