Mini-Tmall
cpe:2.3:a:mini_tmall_project:mini_tmall:*:*:*:*:*:*:*
- <= 20250211
A cross-site scripting (XSS) vulnerability has been identified in Mini-Tmall versions prior to 20250211. The issue resides in the Admin Name Handler component, specifically within the /admin file. This vulnerability allows remote attackers to inject malicious scripts, which could be executed in the context of the user's browser.
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
To reproduce this vulnerability, access the admin panel of a Mini-Tmall installation prior to 20250211. Enter a script payload into the relevant module, which will trigger the cross-site scripting vulnerability by executing the injected script.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.