Legcord 1.1.0 至 1.3.0 版本中存在一个路径遍历漏洞,该漏洞位于主题 IPC(进程间通信)处理器中,允许通过未经验证的主题 ID,使 Discord 页面中的脚本突破主题目录的限制。攻击者若在 Discord 原始来源中执行脚本(例如通过跨站脚本攻击 XSS),可利用 、 和 等功能,在主题目录之外执行本地可执行程序、递归删除目录以及写入任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet