Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kibana Unrestricted Upload of File with Dangerous Type Can Lead to XSS
Vulnerability Description
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Elastic Kibana 安全漏洞
Vulnerability Description
Elastic Kibana是Elastic公司的一个可用数据可视化仪表板软件。 Elastic Kibana 8.12.0之前版本存在安全漏洞,该漏洞源于未限制危险类型文件上传,可能导致在浏览器中执行任意JavaScript。
CVSS Information
N/A
Vulnerability Type
N/A