Computer Vision Annotation Tool(CVAT)是cvat.ai开源的一种用于计算机视觉的交互式视频和图像注释工具。 Computer Vision Annotation Tool(CVAT) 2.4.7版本至2.18.0版本存在跨站脚本漏洞,该漏洞源于如果具有创建任务或编辑现有任务权限的恶意用户可以诱骗其他登录用户访问恶意构建的URL,他们就可以代表该用户发起任何API调用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-47172 | 5.4 MEDIUM | Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpoints |
| CVE-2024-47064 | Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpoints |
No comments yet