JGraph draw.io是JGraph的一个可配置的图表/白板可视化应用程序。 JGraph draw.io 18.1.2之前版本存在安全漏洞,该漏洞源于将敏感信息暴露给未经授权的 Actor。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jgraph | jgraph/drawio | unspecified ~ 18.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Drawio before 18.1.2 is susceptible to server-side request forgery via the /service endpoint in jgraph/drawio. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1815.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet