Chaterm 在 0.12.1 之前的版本中存在一个登录跨站请求伪造(CSRF)漏洞,攻击者无需通过 OAuth 状态验证即可通过发送 chaterm:// 回调注入登录状态。攻击者可以从网页触发精心构造的回调,并使用攻击者控制的 userInfo 信息,使受害者登录到攻击者的账户,从而导致默认的数据同步上传已保存的主机、密码和私钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet