A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 20 Jan 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Technical-laohu
Technical-laohu mpay |
|
| Vendors & Products |
Technical-laohu
Technical-laohu mpay |
Mon, 19 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. | |
| Title | technical-laohu mpay User Center cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-01-19T11:02:05.822Z
Reserved: 2026-01-18T13:59:43.860Z
Link: CVE-2026-1151
No data.
Status : Received
Published: 2026-01-19T11:15:50.047
Modified: 2026-01-19T11:15:50.047
Link: CVE-2026-1151
No data.