HAWKI是德国HAWK Digital Environments团队的一个基于 OpenAI API 的大学教学界面。 HAWKI存在安全漏洞,该漏洞源于没有正确筛选POST参数,导致存在路径遍历漏洞。攻击者可利用该漏洞覆Web服务器具有写权限的所有文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Interaction Design Team at the University of Applied Sciences and Arts in Hildesheim/Germany | HAWKI | versions before commit 146967f | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-25977 | Session Fixation | |
| CVE-2024-25976 | Reflected Cross-Site-Scripting (XSS) |
No comments yet