Twine 2 桌面版 2.12.0 及更早版本中存在一个跨站脚本(XSS)漏洞,位于 函数中。该漏洞会导致在编辑器窗口中执行从导入的故事文件中的标记(markup)。攻击者可构造一个恶意故事文件,其中的脚本通过调用 的 IPC 桥接机制,写入并打开一个 批处理文件,从而在用户权限下执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet