# ETQ Reliance CG 跨站脚本漏洞
```markdown
## 概述
ETQ Reliance CG(遗留)平台中的 `SQLConverterServlet` 组件存在反射型跨站脚本(XSS)漏洞。
## 影响版本
该漏洞影响 SE.2025.1 之前的版本。
## 漏洞细节
`SQLConverterServlet` 被错误地暴露给已认证用户,攻击者可通过诱使用户点击构造的恶意链接,触发反射型 XSS 漏洞。
## 漏洞影响
此漏洞可能导致攻击者在受害用户的上下文中执行未经授权的脚本,进而引发会话劫持、信息泄露或执行恶意操作。
```
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the SQLConverterServlet component. This vulnerability requires user interaction, such as clicking a crafted link, and may result in execution of unauthorized scripts in the user's context. The affected servlet was unnecessarily exposed to authenticated users and has since been disabled in version SE.2025.1. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-34141.yaml | POC详情 |
标题: How We Accidentally Discovered a Remote Code Execution Vulnerability in ETQ Reliance › Searchlight Cyber -- 🔗来源链接
标签: technical-description
神龙速读暂无评论