A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Metrics
Affected Vendors & Products
References
History
Mon, 19 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. | |
| Title | technical-laohu mpay User Center cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-01-19T11:02:05.822Z
Reserved: 2026-01-18T13:59:43.860Z
Link: CVE-2026-1151
No data.
Status : Received
Published: 2026-01-19T11:15:50.047
Modified: 2026-01-19T11:15:50.047
Link: CVE-2026-1151
No data.
OpenCVE Enrichment
No data.