HAWKI是德国HAWK Digital Environments团队的一个基于 OpenAI API 的大学教学界面。 HAWKI存在跨站脚本漏洞,该漏洞源于使用login或logout功能时,应用程序不会更改会话令牌,导致受害者的账户被接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Interaction Design Team at the University of Applied Sciences and Arts in Hildesheim/Germany | HAWKI | versions before commit 146967f | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-25976 | Reflected Cross-Site-Scripting (XSS) | |
| CVE-2024-25975 | Arbitrary File Overwrite |
No comments yet