Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands when the victim imports a malicious data file containing JavaScript in the objectId parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BloodHound 跨站脚本漏洞
Vulnerability Description
BloodHound是一款通过图论揭示Active Directory环境中的隐藏关系和攻击路径的JavaScript应用程序。 Bloodhound 中存在跨站脚本漏洞。该漏洞源于产品的components/Modals/HelpTexts/GenericAll/GenericAll.jsx 允许远程攻击者在受害者导入objectId参数中包含JavaScript的恶意数据文件时执行任意系统命令。以下产品及版本受到影响:Bloodhound 4.0.2 之前版本。
CVSS Information
N/A
Vulnerability Type
N/A