天下漏洞,尽知其名
MEDIUM

CVE-2026-102292 MateisHomePage-Website 跨站脚本漏洞

影响攻击者可远程注入脚本实施跨站脚本攻击

AI 研判

MateisHomePage-Website 的 users.php 文件存在跨站脚本漏洞,攻击者可通过操纵 Search 参数注入恶意脚本。该漏洞可远程触发,且利用代码已公开,存在被实际利用的风险。

影响范围

MateisHomePage-Website

影响 coolbeans1212 MateisHomePage-Website 截至提交 ea2a4226deeca27ab1fb9df0552ec76444547811 的版本。由于该项目采用滚动发布模式,暂无具体受影响或修复版本号公开信息。

漏洞详情

该漏洞属于反射型跨站脚本(XSS),成因是 users.php 在处理 Search 参数时未对用户输入进行充分的过滤或转义。攻击者可构造包含恶意脚本的链接,诱导受害者访问,脚本将在受害者浏览器中执行。

利用条件与风险

利用需诱导用户点击恶意链接或访问被篡改的页面,属于远程攻击。由于利用代码已公开,实战中被扫描和利用的可能性较高,但 CVSS 评分仅为 4.3,整体风险中等。

修复建议

官方已发布补丁,补丁标识为 6406308df9771d2fd477b56dafe4878dd846df6e,建议尽快应用该补丁修复。临时缓解措施包括对 Search 参数进行严格的输入过滤与输出编码,暂无其他公开信息。

原始情报

A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipulation of the argument Search causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 6406308df9771d2fd477b56dafe4878dd846df6e. Applying a patch is the recommended action to fix this issue.