在 imgproxy 4.0.17 及更早版本中发现了一个漏洞。该漏洞影响 SVG 处理组件中的 文件的 函数。通过执行特定操作可导致跨站脚本(XSS)攻击。该攻击可远程发起。相关利用代码已公开,可能被恶意利用。该项目已通过 Issue 报告提前获知此问题,但至今尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | imgproxy | 4.0.0 |
cpe:2.3:a:imgproxy:imgproxy:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105571 | 7.3 HIGH | PickMall Lilishop Mobile Binding bindMobile improper authorization |
| CVE-2026-105707 | 5.3 MEDIUM | uptrace user_handler.go Login information exposure |
| CVE-2026-105572 | 4.3 MEDIUM | PickMall Lilishop Buyer Invoice List receipt authorization |
No comments yet