Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, the (NT)LM hashes of the user are sent with the HTTP request. This allows an attacker to collect these hashes, crack them, and potentially compromise the computer. (ROAR can be configured for automatic access. Also, access can occur if the user clicks.)
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ignite Realtime Spark 信息泄露漏洞
Vulnerability Description
Ignite Realtime Spark是Ignite Realtime社区的一款开源、跨平台的实时协作客户端应用程序。 Ignite Realtime Spark 2.8.3版本(Windows)中存在信息泄露漏洞。远程攻击者可利用该漏洞获取并破解哈希值,访问用户账户,提升权限。
CVSS Information
N/A
Vulnerability Type
N/A