Puncsky Touchbase.ai是Puncsky个人开发者的一个用于人际关系的 web 平台。 touchbase.ai 2.0之前版本存在输入验证错误漏洞,攻击者可利用该漏洞控制网站,在某些情况下甚至会导致XSS攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| puncsky | touchbase.ai | < 2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-26218 | 8.0 HIGH | HTML Injection in touchbase.ai |
| CVE-2020-26221 | 8.0 HIGH | Stored Cross Site Scripting in touchbase.ai |
| CVE-2020-26220 | 3.5 LOW | Information exposure in touchbase.ai |
No comments yet