漏洞描述 cool-admin-java是COOL个人开发者的一个后台权限管理框架。 cool-admin-java v1.0版本存在跨站脚本漏洞。攻击者利用该漏洞可以通过向internet pictures字段注入特制有效载荷来执行任意 Web 脚本或 HTML。
相关漏洞推荐 POC CVE-2013-3827: Javafaces LFI POC CVE-2017-12637: SAP NetWeaver Application Server Java 7.5 - Local File Inclusion POC CVE-2020-6287: SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin Addition POC CVE-2021-37573: Tiny Java Web Server - Cross-Site Scripting POC CVE-2022-29078: Node.js Embedded JavaScript 3.1.6 - Template Injection POC CVE-2023-29827: Embedded JavaScript(EJS) 3.1.6 - Template Injection POC CVE-2025-46822: Java-springboot-codebase 1.1 - Arbitrary File Read POC CVE-2017-12149: Java/Jboss Deserialization [RCE] POC CVE-2018-15531: JavaMelody XXE POC javamelody-detect: JavaMelody Monitoring Exposed POC jinjava-ssti: Jinjava - Server Side Template Injection POC javascript-env-config: JavaScript Environment Configuration - Detect POC javascript-env: JavaScript Environment Configuration - Detect