Fabric.js 的 loadFromJSON 服务端请求伪造(SSRF)漏洞。该漏洞允许远程攻击者在受影响的 Fabric.js 安装环境中泄露敏感信息。利用此漏洞需要与该库进行交互,但具体的攻击向量可能因具体实现方式的不同而有所差异。 具体缺陷存在于 方法的实现中。该问题源于在访问资源前未对 URI 进行适当的验证。攻击者可利用该漏洞不当访问网络资源。该漏洞编号为 ZDI-CAN-29318。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet