Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can result in CSRF attack, possible leak of anti-CSRF token. This attack appears to be exploitable via malicious request against WebSocket handshake endpoint. This vulnerability appears to have been fixed in 1.14.0 and later.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Taoensso Sente 跨站请求伪造漏洞
Vulnerability Description
Taoensso Sente是一款实时网络通信程序。 Taoensso Sente 1.14.0之前版本中WebSocket存在跨站请求伪造漏洞。攻击者可利用该漏洞执行未授权的操作。
CVSS Information
N/A
Vulnerability Type
N/A