Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
艺电 Electronic Arts Origin 注入漏洞
Vulnerability Description
Electronic Arts Origin是美国艺电(Electronic Arts)公司的一款游戏管理平台。该平台包括电子软件分发、数字版权管理及社交系统等功能。 EA Origin 10.5.36版本(Windows)中的客户端存在注入漏洞。攻击者可借助origin2://game/launch URL利用该漏洞绕过底层的AngularJS沙盒并执行代码。
CVSS Information
N/A
Vulnerability Type
N/A