Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Squaredup 跨站请求伪造漏洞
Vulnerability Description
Squaredup是英国Squaredup公司的一个可为云环境提供数据监控功能的Web服务。 SquaredUp before version 4.6.0 存在跨站请求伪造漏洞,攻击者可利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A