Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MySource Matrix 跨站脚本攻击漏洞
Vulnerability Description
MySource Matrix 3.8之后的版本可让远程攻击者通过sq_content_src参数中MIME编码的URL,将应用程序用作HTTP代理服务器,以该服务器的IP地址来访问任意站点并执行跨站脚本攻击(XSS)。
CVSS Information
N/A
Vulnerability Type
N/A