Scripta eScriptorium是Scripta团队的一个手写文本识别与标注平台。 Scripta eScriptorium 26.04.1及之前版本存在服务端请求伪造漏洞,该漏洞源于METS和IIIF导入URI处理不当,且IMPORT_ALLOWED_DOMAINS设置默认为'*',未应用地址过滤、重定向限制或超时,可能导致远程认证用户通过mets_uri或iiif_uri参数使服务器向内部主机发起任意HTTP请求,包括云实例元数据服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Scripta | eScriptorium | ≤ 26.4.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Scripta | eScriptorium | 0 ~ 26.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18258 | 8.8 HIGH | Authorization Bypass Through User-Controlled Key in eScriptorium |
| CVE-2026-18277 | 7.1 HIGH | Missing Authorization in eScriptorium |
| CVE-2026-18275 | 6.5 MEDIUM | Authorization Bypass Through User-Controlled Key in eScriptorium |
| CVE-2026-18276 | 4.3 MEDIUM | Missing Authorization in eScriptorium |
No comments yet