Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url parameter to the /api/proxy URI, as demonstrated by an XMLHttpRequest call with an 'email:"attacker@example.com"' request, which can be followed by a password reset.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cozy 跨站脚本漏洞
Vulnerability Description
Cozy是一套个人云平台。该平台具有文件存储与管理、应用程序备份以及日程管理等功能。 Cozy中存在跨站脚本漏洞。远程攻击者可借助发送到/api/proxy URI的‘url’参数中的JavaScript代码利用该漏洞获取管理员访问权限。
CVSS Information
N/A
Vulnerability Type
N/A