Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the /_matrix/client/r0/auth/*/fallback/web or /_matrix/client/unstable/auth/*/fallback/web Synapse endpoints.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Matrix Synapse 跨站脚本漏洞
Vulnerability Description
Matrix Synapse是英国Matrix.org基金会的一款矩阵管理服务器的实现。 Matrix Synapse 1.21.0之前版本存在跨站脚本漏洞,该漏洞源于/_matrix/client/r0/auth/m.login.recaptcha或/ _matrix / client / r0。
CVSS Information
N/A
Vulnerability Type
N/A