Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2022-25229
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Popcorn Time 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Popcorn Time是一个多平台的免费软件 BitTorrent 客户端。 Popcorn Time 0.4.7 版本存在安全漏洞,该漏洞源于 setting 页面 Movies API Server(s) 字段可以注入存储型跨站脚本。nodeIntegration 配置设置为允许 webpage 使用 NodeJs 功能,攻击者可以利用它来运行操作系统命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
-Popcorn Time 0.4.7 -
II. Public POCs for CVE-2022-25229
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2022-25229
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2022-25229

No comments yet


Leave a comment