Microsoft Copilot Studio是美国微软(Microsoft)公司的一个人工智能聊天机器人。 Microsoft Copilot Studio存在跨站脚本漏洞,该漏洞源于网页生成期间的输入中和不当,导致通过网络提升权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft Copilot Studio | N/A | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-49035 | 8.7 HIGH | Partner.Microsoft.Com Elevation of Privilege Vulnerability |
| CVE-2024-49052 | 8.2 HIGH | Microsoft Azure PolicyWatch Elevation of Privilege Vulnerability |
| CVE-2024-49053 | 7.6 HIGH | Microsoft Dynamics 365 Sales Spoofing Vulnerability |
No comments yet