Reddit Moderator Toolbox(reddit-moderator-toolbox)在 4.0.14 版本之前,其 removalreasons 模块中存在一个存储型跨站脚本(XSS)漏洞。该漏洞会将 subreddit 工具箱 wiki 字段直接插入到弹出窗口的 HTML 中,而未进行适当的编码。攻击者若能编辑工具箱的 wiki 页面,便可在 pmsubject、header 或 reason 标题等字段中植入 JavaScript 代码,从而冒充版主身份,利用其 Reddit 会话权限进行操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| toolbox-team | reddit-moderator-toolbox | < 4.0.14 |
affected |
4.0.14 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| toolbox-team | reddit-moderator-toolbox | 0 ~ 4.0.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet